offensive-supply-chain
Comprehensive offensive methodology for software supply chain attacks covering the full kill chain from reconnaissance through exploitation. Addresses dependency confusion across npm, PyPI, and NuGet ecosystems where internal registry override allows an attacker to inject malicious packages that shadow private dependencies. Covers typosquatting techniques for popular packages, compromised package injection via maintainer account takeover or social engineering, and build system attacks through Makefile injection, setup.py install hooks, and npm postinstall scripts. . Use when performing authorized red-team, pentest, or research work involving supply chain.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-supply-chain/SKILL.md
- skills/offensive-supply-chain/LICENSE
- skills/offensive-supply-chain/README.md
- skills/offensive-supply-chain/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.