Guys this is absolutely genius and nuts! I have never seen anything like this before. This guy got access to paypal json and saw some private packages.. created public ones with a similar name and then made them do bad things, then thing because firewalls will shut those down.. he used DNS


DNS requests are practically safe so firewalls allow them


11:05 chrome root https://youtu.be/qpC1YH0FhuY


https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610