METAL for iPhone

Read AI news in the METAL app.

Download METAL and discover fresh AI stories every day.

Download on the App Store

For iPhone · Free download

Search for METAL AI Magazine in the App Store on your iPhone.

METAL

AI GlossaryㅇSafety and controversy

dependency confusion

A supply-chain attack in which an attacker registers an unclaimed package name before anyone else, planting malicious code there in advance

In plain words

In a dependency confusion attack, when a program pulls in a code component by name and that name hasn't been claimed by anyone yet, an attacker registers it first and plants their own malicious code there. When building software, developers often just write down the name of someone else's code package and let it get pulled in automatically — and this attack exploits exactly that gap.

Here's an analogy. Imagine a company memo says "send this document to Room 302," but Room 302 hasn't actually been assigned to anyone yet. If someone secretly registers Room 302 under their own name first, every document sent based on the memo ends up in that person's hands. The same thing can happen in the software world.

Recently, the rise of AI coding agents has made this attack much easier to pull off. A human might pause for a moment when seeing an unfamiliar name, but an agent will run the install command exactly as written in the documentation — so a single unclaimed name planted in advance by an attacker can open a path all the way into a company's internal network.

How it shows up in the news

The article calls this a "name-squatting (dependency confusion)" attack, explaining that the problem arises when a company's llms.txt file points to a package or domain that doesn't actually exist. A common misconception: this isn't some new attack invented by AI — it's a long-known technique in software supply chains. What's different this time is simply that a coding agent, rather than a human, automatically executed the command.

Try it yourself

If you want to check this risk in a project or documentation you manage, try the following.

  1. Open your project's dependency list (the file listing the names of components to be installed).
  2. Check whether each name is actually registered in a public repository and owned by a trustworthy party.
  3. If there's a name that's only been used internally but hasn't yet been registered in the public repository, register it yourself first to claim it.
  4. If you're having an AI coding agent handle documentation-based tasks, add a step where a human reviews the names the agent intends to install before execution.

See also

Stories using this term

Browse every entry