Toxic Dependencies
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Third-party libraries could be introducing vulnerabilities or malicious code into your system.
- Prevalence
- Occasional
- Exploitability
- Moderate
- Impact
- Devastating
What are toxic dependencies?
Toxic dependencies are a software supply chain vulnerability in which third-party libraries introduce security flaws or malicious code into your application. A dependency may contain a known vulnerability that was never patched, or may have been deliberately compromised by an attacker. Because most applications are built largely from open-source packages, one bad dependency can affect thousands of systems.
What you'll learn
- How vulnerable and compromised libraries end up in your application
- What Log4Shell, SolarWinds and Heartbleed show about supply chain risk
- How pinned versions, dependency scanning and prompt patching reduce exposure
Where this lesson counts
OWASP Top 10
Compromised or malicious third-party packages, build tooling and update channels reach production through you.
Learn more about A03This lesson includes
-
Toxic Dependencies lab
Revisit the incidents that made dependencies a security problem: Log4Shell, Rails mass assignment and the GitHub hack, XcodeGhost, SolarWinds and Heartbleed. Then play the attacker with a simulated Heartbleed memory dump, find the login credentials inside and use them.
-
How to prevent Toxic Dependencies
The prevention guide covers eight approaches:
- Automate Your Build and Deployment Processes
- Deploy Known-Good Versions of Software
- Be Careful of Private Dependencies
- Scan Your Dependency Tree for Security Risks
- Keep on Top of Security Bulletins
- Perform Regular Code Reviews
- Make Penetration Testing Part of Your Development Lifecycle
- Use a Dependency Manager
-
Toxic Dependencies quiz
Two questions. Passing marks the lesson complete.
Sources
- npm npm: Dependency management for Node modules.
- pip Python Packaging Authority: Dependency management for Python packages.
- Bundler Bundler: Dependency management for Ruby gems.
- Maven Apache Maven: Dependency management for Java jars.
- Gradle Gradle: Dependency management for Java jars.
- NuGet NuGet: Dependency management for .NET.
- Composer Composer: Dependency management for PHP.
Related lessons
Browse all 45 lessons
Slopsquatting (LLM Supply Chain)
When LLM tools hallucinate package names, attackers can register malicious packages with those names.
Malvertising
Embedded adverts are a common target for hackers.
Insecure Design
Security begins before you start writing code.
Prototype Pollution
If an attacker can access and modify prototype objects in JavaScript, you are in danger.