<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Raja Nagori</title>
    <description>The latest articles on DEV Community by Raja Nagori (@raja_nagori).</description>
    <link>https://dev.to/raja_nagori</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4069913%2F3fd90b17-73b1-4fd4-a5a4-4ebba1c6079b.png</url>
      <title>DEV Community: Raja Nagori</title>
      <link>https://dev.to/raja_nagori</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/raja_nagori"/>
    <language>en</language>
    <item>
      <title>Tenant Isolation Is a Boundary, Not a Filter</title>
      <dc:creator>Raja Nagori</dc:creator>
      <pubDate>Tue, 25 Aug 2026 13:30:00 +0000</pubDate>
      <link>https://dev.to/raja_nagori/tenant-isolation-is-a-boundary-not-a-filter-1mcd</link>
      <guid>https://dev.to/raja_nagori/tenant-isolation-is-a-boundary-not-a-filter-1mcd</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxagpapgakcr0s44lt824.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxagpapgakcr0s44lt824.png" alt="High Level Diagram" width="800" height="1182"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If two customers share a platform and isolation is “UI only,” you have a liability.&lt;/p&gt;

&lt;h2&gt;
  
  
  Problem
&lt;/h2&gt;

&lt;p&gt;Every request must answer: &lt;strong&gt;whose data is this?&lt;/strong&gt; If the client supplies &lt;code&gt;orgId&lt;/code&gt; and you politely believe it, you already lost.&lt;/p&gt;

&lt;h2&gt;
  
  
  Solution concept
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Authenticate the caller
&lt;/li&gt;
&lt;li&gt;Load memberships
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bind tenant context&lt;/strong&gt; for this request
&lt;/li&gt;
&lt;li&gt;Scope DB reads/writes to that tenant
&lt;/li&gt;
&lt;li&gt;Keep files/workspaces under the same identity
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The org dropdown is a reminder, not the control plane.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh7wu7rs15gl5w55i2j1g.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh7wu7rs15gl5w55i2j1g.png" alt="Seq Diagram" width="702" height="405"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Residual risk
&lt;/h2&gt;

&lt;p&gt;Rare bypass paths need review. App filters without DB enforcement are thinner. Isolation shrinks blast radius, it is not absolute safety.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try a real console - leave feedback
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://nightingale-security.com/" rel="noopener noreferrer"&gt;nightingale-security.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dashboard.nightingale-security.com/register" rel="noopener noreferrer"&gt;Register&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dashboard.nightingale-security.com/login" rel="noopener noreferrer"&gt;Login&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Review / discuss: &lt;a href="https://github.com/RAJANAGORI/Nightingale/discussions/11" rel="noopener noreferrer"&gt;GitHub Discussions #11&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>architecture</category>
      <category>cloud</category>
      <category>devops</category>
    </item>
    <item>
      <title>Malicious updates: why “just npm update” is a security decision</title>
      <dc:creator>Raja Nagori</dc:creator>
      <pubDate>Thu, 20 Aug 2026 15:00:00 +0000</pubDate>
      <link>https://dev.to/raja_nagori/malicious-updates-why-just-npm-update-is-a-security-decision-1h53</link>
      <guid>https://dev.to/raja_nagori/malicious-updates-why-just-npm-update-is-a-security-decision-1h53</guid>
      <description>&lt;p&gt;Routine upgrades can introduce new exfil channels behind familiar package names.&lt;/p&gt;

&lt;h2&gt;
  
  
  Problem
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;npm update&lt;/code&gt; is not a hygiene chore. It is a content-distribution event for every package in range.&lt;/p&gt;

&lt;p&gt;Split “security hotfix” lanes from “dependency refresh” lanes so urgency cannot be used to skip review.&lt;/p&gt;

&lt;h2&gt;
  
  
  Solution concept
&lt;/h2&gt;

&lt;p&gt;Ship one control at a time, measure bypasses, then add the next. A single enforced check beats a binder of unenforced best practices.&lt;/p&gt;

&lt;p&gt;Treat dependency bumps as deployments: review, stage, canary, then promote. Especially for packages that run code at install or import time.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fw5loin8h6eyf8vej8961.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fw5loin8h6eyf8vej8961.png" alt="High Level Overview" width="699" height="454"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;App depends on a helper with caret/range policy&lt;/li&gt;
&lt;li&gt;Malicious version publishes under the same name&lt;/li&gt;
&lt;li&gt;Update command pulls the trojanized release&lt;/li&gt;
&lt;li&gt;Runtime or install path executes new behavior&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpr1498sjo4vlciqjk2hd.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpr1498sjo4vlciqjk2hd.png" alt="Sequence Diagram" width="800" height="385"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Field notes
&lt;/h2&gt;

&lt;p&gt;Separate bots: one opens dependency PRs, another cannot merge them. Require a short threat note on PRs that touch lockfiles for internet-facing services—“what could a malicious version do here?”&lt;/p&gt;

&lt;h2&gt;
  
  
  Residual risk
&lt;/h2&gt;

&lt;p&gt;You will still miss clever payloads. Pair process with runtime detection; neither alone is enough.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it - then talk back
&lt;/h2&gt;

&lt;p&gt;Explore the concept in &lt;strong&gt;Supply Chain Attack Simulator (SCAS)&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://simulator.rajanagori.in/" rel="noopener noreferrer"&gt;Master supply chain security with real attack scenarios&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RAJANAGORI/supply-chain-attack-simulator#start-here" rel="noopener noreferrer"&gt;Start Here&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://simulator.rajanagori.in/guide.html?p=scenario-guides%2Fzero-to-hero%2FZERO_TO_HERO_SCENARIO_04.md" rel="noopener noreferrer"&gt;Malicious Update Supply Chain Attack&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;If you face any issues - &lt;a href="https://github.com/RAJANAGORI/supply-chain-attack-simulator/issues/new/choose" rel="noopener noreferrer"&gt;Github Issues - RAJANAGORI&lt;/a&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Stop Rebuilding Your Pentest Lab for Every Engagements</title>
      <dc:creator>Raja Nagori</dc:creator>
      <pubDate>Wed, 19 Aug 2026 11:30:00 +0000</pubDate>
      <link>https://dev.to/raja_nagori/stop-rebuilding-your-pentest-lab-for-every-engagements-3fb2</link>
      <guid>https://dev.to/raja_nagori/stop-rebuilding-your-pentest-lab-for-every-engagements-3fb2</guid>
      <description>&lt;p&gt;Nightingale is a Docker pentest stack with a browser Command Center terminals, scans, VPN, VS Code, and team controls in one place.&lt;/p&gt;

&lt;p&gt;I used to burn the first hour of an engagement on setup: install the missing package, fix the broken VPN route, sync notes from three terminals, then remember the new analyst still does not have a working lab.&lt;/p&gt;

&lt;p&gt;That hour never shows up in the report. It still costs the client.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Nightingale&lt;/strong&gt; flips the default. One Docker image, 200+ tools, and a web Command Center so the lab is the same whether you are on a laptop or a hosted console.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2hw3d1y7wv6vh0retfju.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2hw3d1y7wv6vh0retfju.png" alt="Nightingale homepage security testing at engineering speed" width="800" height="401"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The pain (in one sentence)
&lt;/h2&gt;

&lt;p&gt;Toolchains sprawl across hosts, environments drift, and onboarding a tester still takes longer than the first recon pass.&lt;/p&gt;

&lt;h2&gt;
  
  
  What you actually get
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Surface&lt;/th&gt;
&lt;th&gt;Why it matters&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Multi-terminal + file explorer&lt;/td&gt;
&lt;td&gt;Parallel shells in the browser; tree stays with your cwd&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security Scans / Playbooks / Schedules&lt;/td&gt;
&lt;td&gt;Queue tools, chain steps, schedule repeats, export Markdown&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;VPN&lt;/td&gt;
&lt;td&gt;Upload &lt;code&gt;.ovpn&lt;/code&gt;, connect in an isolated container for HTB/THM-style labs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;VS Code in-browser&lt;/td&gt;
&lt;td&gt;Edit without leaving the engagement&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Users + MFA + audit&lt;/td&gt;
&lt;td&gt;Shared console without shared accountability gaps&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Optional AI&lt;/td&gt;
&lt;td&gt;Command suggestions + scan explainers with your own key&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Same product idea on &lt;a href="https://nightingale-security.com/" rel="noopener noreferrer"&gt;nightingale-security.com&lt;/a&gt;  open core under OWASP, Black Hat Arsenal track record, pull from GHCR or use the hosted dashboard.&lt;/p&gt;

&lt;h2&gt;
  
  
  Walk the UI (screenshots)
&lt;/h2&gt;

&lt;p&gt;Sign in (or register a tenant first):&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fb10wmfzggmtchysrxtw1.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fb10wmfzggmtchysrxtw1.png" alt="Nightingale Command Center login" width="800" height="401"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Land in the console shell + explorer for the active org/engagement:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq3h0mqhhczt0sxcklgka.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq3h0mqhhczt0sxcklgka.png" alt="Web shell and file explorer" width="800" height="401"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Submit scans without babysitting a random &lt;code&gt;tmux&lt;/code&gt; session:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F51bpg49dsqy33c7qkbfz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F51bpg49dsqy33c7qkbfz.png" alt="Submit your scan" width="800" height="401"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Connect lab VPN without killing your console network:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Feyrzhhuone95evpr0unh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Feyrzhhuone95evpr0unh.png" alt="VPN Management" width="800" height="455"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Manage who can touch the console:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8b5om7u6a3l28so8emok.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8b5om7u6a3l28so8emok.png" alt="User Management and MFA" width="800" height="401"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick start (hosted)
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Register:&lt;/strong&gt; &lt;a href="https://dashboard.nightingale-security.com/register" rel="noopener noreferrer"&gt;dashboard.nightingale-security.com/register&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Login:&lt;/strong&gt; &lt;a href="https://dashboard.nightingale-security.com/login" rel="noopener noreferrer"&gt;dashboard.nightingale-security.com/login&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Open &lt;strong&gt;Nightingale Console&lt;/strong&gt;, pick an engagement, run a command or submit a scan.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Quick start (self-host)
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;docker pull ghcr.io/rajanagori/nightingale:stable
docker run &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="nt"&gt;-p&lt;/span&gt; 8080:8080 &lt;span class="nt"&gt;--name&lt;/span&gt; nightingale ghcr.io/rajanagori/nightingale:stable
&lt;span class="c"&gt;# open http://localhost:8080&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Spin it up when the test is scheduled. Tear it down when you are done. No 24/7 lab tax.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this sticks for teams
&lt;/h2&gt;

&lt;p&gt;Engagements are scoped (org + engagement context), so org1 and org2 do not share home dirs, scan history, or VPN configs by accident. That matters when two programs run in parallel and you cannot afford “wrong folder, wrong VPN” mistakes.&lt;/p&gt;

&lt;p&gt;The browser VS Code tab keeps notes and scripts next to the shell. Optional AI settings let you bring your own OpenAI or Azure key for scan explainers useful when you want a first pass narrative over raw tool output, not a black-box vendor model you cannot control.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who this is for
&lt;/h2&gt;

&lt;p&gt;Pentesters and security engineers who want &lt;strong&gt;reproducible tooling&lt;/strong&gt; and a &lt;strong&gt;browser first ops surface&lt;/strong&gt; not another “install these 40 packages” wiki page. Also useful for lab instructors and CTF crews who need the same environment every time someone joins.&lt;/p&gt;

&lt;p&gt;If that sounds like your workflow tax, start here: &lt;a href="https://nightingale-security.com/" rel="noopener noreferrer"&gt;nightingale-security.com&lt;/a&gt; → register → open the console.&lt;/p&gt;

</description>
      <category>security</category>
      <category>docker</category>
      <category>owasp</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Compromised packages: same name, new behavior, old trust</title>
      <dc:creator>Raja Nagori</dc:creator>
      <pubDate>Tue, 18 Aug 2026 15:00:00 +0000</pubDate>
      <link>https://dev.to/raja_nagori/compromised-packages-same-name-new-behavior-old-trust-19k3</link>
      <guid>https://dev.to/raja_nagori/compromised-packages-same-name-new-behavior-old-trust-19k3</guid>
      <description>&lt;p&gt;Trust is sticky. Version bumps can ship new exfil while APIs stay stable.&lt;/p&gt;

&lt;h2&gt;
  
  
  Problem
&lt;/h2&gt;

&lt;p&gt;Same package name. Familiar API. New version. Hidden side effect on load or on a hot method. That is maintainer/release compromise - not a typo.&lt;/p&gt;

&lt;p&gt;For top-N packages by import graph reach, require human approval on version bumps—even patch lines.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0rdkc7uxnd6w3pekohad.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0rdkc7uxnd6w3pekohad.png" alt="High Level Overview" width="684" height="447"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Solution concept
&lt;/h2&gt;

&lt;p&gt;Ship one control at a time, measure bypasses, then add the next. A single enforced check beats a binder of unenforced best practices.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Pin + human review for critical deps
&lt;/li&gt;
&lt;li&gt;Verify provenance attestations when available
&lt;/li&gt;
&lt;li&gt;Alert on novel egress from package code
&lt;/li&gt;
&lt;li&gt;Prefer smaller dependency surfaces for trust boundaries&lt;/li&gt;
&lt;/ul&gt;

&lt;ol&gt;
&lt;li&gt;Users already depend on a trusted package name&lt;/li&gt;
&lt;li&gt;Maintainer account or release pipeline is abused&lt;/li&gt;
&lt;li&gt;New version preserves exports but adds a beacon path&lt;/li&gt;
&lt;li&gt;Consumers update routinely and inherit the behavior&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fiofaaeioiiarmpqgev00.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fiofaaeioiiarmpqgev00.png" alt="Sequence Diagram" width="697" height="442"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Field notes
&lt;/h2&gt;

&lt;p&gt;High-reach libraries (HTTP clients, auth helpers, logging) deserve slower upgrade trains. A patch bump that adds network calls to unfamiliar hosts is a stronger signal than a CVSS score alone.&lt;/p&gt;

&lt;h2&gt;
  
  
  Residual risk
&lt;/h2&gt;

&lt;p&gt;Authorized malicious publishes beat signature checks. Layer identity, behavior, and blast-radius reduction.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it - talk back
&lt;/h2&gt;

&lt;p&gt;Explore the concept in &lt;strong&gt;Supply Chain Attack Simulator (SCAS)&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://simulator.rajanagori.in/" rel="noopener noreferrer"&gt;Master supply chain security with real attack scenarios&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RAJANAGORI/supply-chain-attack-simulator#start-here" rel="noopener noreferrer"&gt;Start Here&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://simulator.rajanagori.in/guide.html?p=scenario-guides%2Fzero-to-hero%2FZERO_TO_HERO_SCENARIO_03.md" rel="noopener noreferrer"&gt;Compromised Package Supply Chain Attack&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;If you face any issues - &lt;a href="https://github.com/RAJANAGORI/supply-chain-attack-simulator/issues/new/choose" rel="noopener noreferrer"&gt;Github Issues - RAJANAGORI&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>javascript</category>
      <category>npm</category>
      <category>appsec</category>
    </item>
    <item>
      <title>Dependency confusion in one table: internal scope vs public higher version</title>
      <dc:creator>Raja Nagori</dc:creator>
      <pubDate>Thu, 13 Aug 2026 15:00:00 +0000</pubDate>
      <link>https://dev.to/raja_nagori/dependency-confusion-in-one-table-internal-scope-vs-public-higher-version-2joj</link>
      <guid>https://dev.to/raja_nagori/dependency-confusion-in-one-table-internal-scope-vs-public-higher-version-2joj</guid>
      <description>&lt;h2&gt;
  
  
  Problem
&lt;/h2&gt;

&lt;p&gt;Your CI asks for an internal package. The public registry answers first with &lt;code&gt;999.999.999&lt;/code&gt;. Installers that maximize version will take it. That is dependency confusion no phishing required.&lt;/p&gt;

&lt;p&gt;Print the resolved registry host in CI logs and alert on public hosts for private scopes. Make confusion visible.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8usx5ikyldcuyxj49j6g.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8usx5ikyldcuyxj49j6g.png" alt="High Level Overview" width="800" height="462"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Solution concept
&lt;/h2&gt;

&lt;p&gt;Ship one control at a time, measure bypasses, then add the next. A single enforced check beats a binder of unenforced best practices.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Scope + registry map for every internal namespace.&lt;/li&gt;
&lt;li&gt;Exact pins; no caret/range on private packages.&lt;/li&gt;
&lt;li&gt;Assert resolved URL host in CI against an allowlist.&lt;/li&gt;
&lt;li&gt;Treat lockfile resolved fields as security-relevant artifacts.&lt;/li&gt;
&lt;li&gt;Internal package exists only on a private registry&lt;/li&gt;
&lt;li&gt;Build config also searches the public registry&lt;/li&gt;
&lt;li&gt;Attacker publishes the same name with a higher version&lt;/li&gt;
&lt;li&gt;Installer prefers public artifact; malicious code runs&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F48ks2qchdqi9q9pbalmy.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F48ks2qchdqi9q9pbalmy.png" alt="Sequence Diagram" width="799" height="396"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Field notes
&lt;/h2&gt;

&lt;p&gt;Print resolved URLs during install in CI. If an “internal” package suddenly resolves to a public host, treat it as an incident even when tests pass. Scoped registry maps belong in the repo, not only on individual laptops.&lt;/p&gt;

&lt;h2&gt;
  
  
  Residual risk
&lt;/h2&gt;

&lt;p&gt;Misconfigured local &lt;code&gt;.npmrc&lt;/code&gt; bypasses org policy. Verify resolution in the same environment that ships artifacts and not only on a secure bastion.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it, then talk back
&lt;/h2&gt;

&lt;p&gt;Explore the concept in &lt;strong&gt;Supply Chain Attack Simulator (SCAS)&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://simulator.rajanagori.in/" rel="noopener noreferrer"&gt;Master supply chain security with real attack scenarios&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RAJANAGORI/supply-chain-attack-simulator#start-here" rel="noopener noreferrer"&gt;Start Here&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://simulator.rajanagori.in/guide.html?p=scenario-guides%2Fzero-to-hero%2FZERO_TO_HERO_SCENARIO_02.md" rel="noopener noreferrer"&gt;Dependency Confusion Supply Chain Attack&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;If you face any issues - &lt;a href="https://github.com/RAJANAGORI/supply-chain-attack-simulator/issues/new/choose" rel="noopener noreferrer"&gt;Github Issues - RAJANAGORI&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>npm</category>
      <category>python</category>
      <category>devops</category>
    </item>
    <item>
      <title>Typosquatting is not “user error” - it is a package resolution problem</title>
      <dc:creator>Raja Nagori</dc:creator>
      <pubDate>Tue, 11 Aug 2026 15:00:00 +0000</pubDate>
      <link>https://dev.to/raja_nagori/typosquatting-is-not-user-error-it-is-a-package-resolution-problem-40e9</link>
      <guid>https://dev.to/raja_nagori/typosquatting-is-not-user-error-it-is-a-package-resolution-problem-40e9</guid>
      <description>&lt;p&gt;Why lookalike package names bypass review, and how to reason about install-time vs require-time risk.&lt;/p&gt;

&lt;h2&gt;
  
  
  Problem
&lt;/h2&gt;

&lt;p&gt;If your threat model starts at “crypto of the tarball,” you are already late. Most teams lose at &lt;strong&gt;name resolution&lt;/strong&gt;: the wrong package string installs cleanly, exports a familiar API, and executes side effects before any business logic runs.&lt;/p&gt;

&lt;p&gt;Add a CI check that fails on unexpected new package names in the lockfile for protected services. Cheap control, high signal.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyhkmlf5ppdz9w1lqdxir.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyhkmlf5ppdz9w1lqdxir.png" alt="High level overview" width="800" height="461"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Solution concept
&lt;/h2&gt;

&lt;p&gt;Ship one control at a time, measure bypasses, then add the next. A single enforced check beats a binder of unenforced best practices.&lt;/p&gt;

&lt;p&gt;Practical controls:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Control&lt;/th&gt;
&lt;th&gt;Why it helps&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Lockfiles + &lt;code&gt;npm ci&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;Stops casual name drift on install&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Name allowlists in CI&lt;/td&gt;
&lt;td&gt;Fails builds on unexpected package strings&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lifecycle script policy&lt;/td&gt;
&lt;td&gt;Limits install-time execution&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Boot-time network watch&lt;/td&gt;
&lt;td&gt;Catches require-time beacons&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Do not equate “tests passed” with “no side effects on require.”&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Attacker publishes a lookalike name near a popular package&lt;/li&gt;
&lt;li&gt;Developer (or lockfile drift) installs the wrong name&lt;/li&gt;
&lt;li&gt;Malicious module runs at install or first require&lt;/li&gt;
&lt;li&gt;Payload phones home or in safe labs, posts to localhost only&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8ijqdwfwwlw9yfsvgh3h.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8ijqdwfwwlw9yfsvgh3h.png" alt="Sequence diagram for series of operation" width="800" height="433"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Field notes
&lt;/h2&gt;

&lt;p&gt;Watch for packages whose README is a thin clone of a popular project, publish times clustered after a viral blog post about that project, and maintainers with no prior history. In CI, prefer failing on unexpected new package names over paging after exfiltration.&lt;/p&gt;

&lt;h2&gt;
  
  
  Residual risk
&lt;/h2&gt;

&lt;p&gt;Lookalike detection is fuzzy. Attackers iterate names faster than blocklists. Combine identity checks with behavior signals unexpected scripts, unexpected network knowing both have gaps.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it - then talk back
&lt;/h2&gt;

&lt;p&gt;Explore the concept in &lt;strong&gt;Supply Chain Attack Simulator (SCAS)&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://simulator.rajanagori.in/" rel="noopener noreferrer"&gt;Master supply chain security with real attack scenarios&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RAJANAGORI/supply-chain-attack-simulator#start-here" rel="noopener noreferrer"&gt;Start Here&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://simulator.rajanagori.in/guide.html?p=scenario-guides%2Fzero-to-hero%2FZERO_TO_HERO_SCENARIO_01.md" rel="noopener noreferrer"&gt;Typosquatting Supply Chain Attack&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;If you face any issues - &lt;a href="https://github.com/RAJANAGORI/supply-chain-attack-simulator/issues/new/choose" rel="noopener noreferrer"&gt;Github Issues - RAJANAGORI&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>programming</category>
      <category>opensource</category>
      <category>npm</category>
    </item>
  </channel>
</rss>
