jav333d / depconf-poc
Versions of this package have been flagged as malware by Aikido!
Security research - Dependency confusion PoC demonstrating Packagist resolution with autoload code execution. Razer FIUU assessment (Inspectiv).
99.0.1
2026-07-23 05:50 UTC
Requires
- php: >=5.6
This package is auto-updated.
Last update: 2026-07-23 05:50:14 UTC
README
Security Research Only — Razer FIUU Bug Bounty (Inspectiv)
This package demonstrates that Composer's default behavior of checking Packagist.org allows an attacker to publish malicious packages that get installed when private package names are not claimed on the public registry.
- Tester: jaxjaveed (Inspectiv)
- Program: Razer FIUU
- Mechanism: post-install-cmd sends benign HTTP callback to webhook.site