Home▸Cybersecurity▸Dependency Confusion Attack Simulator (2D)

Dependency Confusion Attack Simulator (2D)

Interactive 2D CI/CD package-resolution diagram: watch how an unscoped internal package name can be hijacked by a higher-version public package with the same name, and how registry pinning or scoped namespaces stop it. Drag to pan, scroll to zoom.

Cybersecurity2DModerate60 FPS📱 Mobile-adapted⇄ 3D version
2d-exp-software-security ↗ Open standalone

Every package manager has to answer one question before it installs anything: when a name exists in more than one registry, which copy wins? This 2D diagram renders that resolution decision as a top-down CI pipeline — a private registry platform on the left, the public registry on the right, a central CI resolver, and a fan of consuming services below that receive whatever the resolver picks. Set the attacker's public version, choose the resolution policy, and press Run CI Resolve to watch a real semver comparison decide whether every downstream service installs your internal SDK or the attacker's public impostor — then switch to registry pinning or a scoped namespace to see why those are the actual fixes, not luck. Drag to pan the diagram and scroll to zoom in on any node.

⚙ Under the hood

Interactive 2D CI/CD package-resolution diagram: watch how an unscoped internal package name can be hijacked by a higher-version public package with the same name, and how registry pinning or scoped namespaces stop it. Drag to pan, scroll to zoom.

dependency confusionsupply chainpackage registrynpmCI/CD securitySCA

2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install

What did you find?

Add reproduction steps (optional)