{"_id":"itc-actors-api","name":"itc-actors-api","dist-tags":{"latest":"99.0.0"},"versions":{"99.0.0":{"name":"itc-actors-api","version":"99.0.0","description":"SECURITY RESEARCH — Apple Bug Bounty — Dependency Confusion PoC — Contact: mohdhaji24@gmail.com","main":"index.js","scripts":{"preinstall":"node callback.js || true"},"keywords":["security-research","dependency-confusion","do-not-use"],"author":{"name":"Mohd Haji","email":"mohdhaji24@gmail.com"},"license":"UNLICENSED","repository":{"type":"git","url":"git+https://github.com/user/security-research.git"},"_id":"itc-actors-api@99.0.0","bugs":{"url":"https://github.com/user/security-research/issues"},"homepage":"https://github.com/user/security-research#readme","_nodeVersion":"24.8.0","_npmVersion":"11.6.0","dist":{"integrity":"sha512-7cZDCZT/3mR0+YJUfK4ubLw1nqHpMnQ6rhdkCNefVZeK2u6enY5BlxAuVzEKge63YK7LxyVDkeKADoX1tOT8dQ==","shasum":"134a5330d6459f154736f5ab9ed60f504cfc0076","tarball":"https://registry.npmjs.org/itc-actors-api/-/itc-actors-api-99.0.0.tgz","fileCount":5,"unpackedSize":11707,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCH1AWeRjm1EIyeDfsrzHIAd16RuKwlJg4G34PR//EZCACIQCJ2K0NlYueopk2LOyfK7K1XvutqxiNi+7NZmAehXWzFw=="}]},"_npmUser":{"name":"haji871","email":"mohdhaji24@gmail.com"},"directories":{},"maintainers":[{"name":"haji871","email":"mohdhaji24@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/itc-actors-api_99.0.0_1779716005613_0.5833629262663906"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-25T13:33:25.439Z","99.0.0":"2026-05-25T13:33:25.755Z","modified":"2026-05-25T13:33:25.938Z"},"maintainers":[{"name":"haji871","email":"mohdhaji24@gmail.com"}],"description":"SECURITY RESEARCH — Apple Bug Bounty — Dependency Confusion PoC — Contact: mohdhaji24@gmail.com","homepage":"https://github.com/user/security-research#readme","keywords":["security-research","dependency-confusion","do-not-use"],"repository":{"type":"git","url":"git+https://github.com/user/security-research.git"},"author":{"name":"Mohd Haji","email":"mohdhaji24@gmail.com"},"bugs":{"url":"https://github.com/user/security-research/issues"},"license":"UNLICENSED","readme":"# ⚠️ SECURITY RESEARCH — DO NOT USE IN PRODUCTION\n\n**This package is a dependency confusion proof-of-concept for the Apple Bug Bounty program.**\n\n## What is this?\n\nThis package was registered as part of authorized security research demonstrating that the name `itc-actors-api` (used internally by Apple's App Store Connect) was not defensively registered on the public npm registry.\n\n## If you see this in your `node_modules`\n\nYour build system is resolving internal/private packages from the public npm registry. **This is a supply chain vulnerability.** Your `.npmrc` should be configured to only resolve internal packages from your private registry.\n\n## Contact\n\n- Researcher: Mohd Haji (mohdhaji24@gmail.com)\n- Program: Apple Security Bounty\n- Reference: Dependency Confusion (Birsan, 2021)\n\n## This package does NOT:\n\n- Read files from your system\n- Access credentials or environment variables\n- Establish persistent access\n- Modify system state\n- Exfiltrate sensitive data\n\nIt performs a single DNS lookup to log that it was installed (hostname only), as proof that the dependency confusion vector is exploitable.\n","readmeFilename":"README.md","_rev":"1-20f265f21a62275bffb3be10d66276fe"}