#Typosquat
That's when you go typosquat those invented classes, to inject backdoors into later!
February 12, 2026 at 5:22 PM
npm stands for the typosquat of nom.
March 26, 2026 at 2:19 AM
A Go typosquat impersonating the popular shopspring/decimal library stayed benign for years before shipping a DNS TXT backdoor that executes commands on import.

The legitimate module has 38K+ known importers, making a single-letter typo a high-value target.

socket.dev/blog/popular... #Golang
Popular Go Decimal Library Targeted by Long-Running Typosqua...
A long-running Go typosquat impersonated the popular shopspring/decimal library and used DNS TXT records to execute commands.
socket.dev
May 19, 2026 at 5:31 PM
I'm still a little worried it can be used to typosquat a handle and redirect to a malicious pds
June 14, 2026 at 4:08 PM
Bitsquat/typosquat the actual provider URLs…
May 17, 2026 at 9:46 AM
This is a wild typosquat hiding #NuGet malware:
cc: @campuscodi.risky.biz
socket.dev Socket @socket.dev · Oct 22
🚨 #NuGet Malware: Our research team uncovered malicious NuGet packages impersonating Nethereum via a Cyrillic “e” (homoglyph). The packages XOR-decoded a C2 and exfiltrated mnemonics, private keys, and keystore data.

Read more: socket.dev/blog/malicio...
Malicious NuGet Packages Typosquat Nethereum to Exfiltrate W...
The Socket Threat Research Team uncovered malicious NuGet packages typosquatting the popular Nethereum project to steal wallet keys.
socket.dev
October 22, 2025 at 4:20 AM
Good analysis from @veracode.bsky.social on this typosquat GitHub actions package.
www.veracode.com/blog/malicio...
Malicious NPM Package Found Targeting GitHub By Typosquatting on GitHub Action Packages | Veracode
Application Security for the AI Era | Veracode
www.veracode.com
November 11, 2025 at 2:49 PM
goole.com gotta be my favorite typosquat. like yeah. you're the website for that small town in england. totally.
April 22, 2025 at 7:22 PM
This is an extremely convincing typosquat. Also a good reminder that Google’s AI summaries are not a reliable way to determine whether a package is safe to use. 😵‍💫
socket.dev Socket @socket.dev · Dec 15
🚨 New threat research: An impostor #NuGet package typosquatted a popular .NET tracing library and its author, using homoglyph tricks to blend in, then exfiltrated #Stratis wallet JSON and passwords to a Russian IP address.
Full report →
socket.dev/blog/malicio... #dotnet
Malicious NuGet Package Typosquats Popular .NET Tracing Libr...
Impostor NuGet package Tracer.Fody.NLog typosquats Tracer.Fody and its author, using homoglyph tricks, and exfiltrates Stratis wallet JSON/passwords t...
socket.dev
December 15, 2025 at 4:38 PM
Clever & cutesy malware infection chain, starting with a typosquat domain, "ClickFix-like" setup but actually not ClickFix -- search-ms: handler to attacker network share, fake PDF lure to download and run an MSI-- ultimately another commodity stealer tho. youtu.be/EZ6TEjx7JLw
September 11, 2025 at 1:11 PM
1) accidentally typosquat a popular framework
2) accidentally ransom them out of $10,000
3) accidentally publish malware and accidentally forgot to remove it

I'm sure he's just a very unlucky guy... 😔
April 30, 2026 at 10:26 PM
📌 Supply Chain & AI Rules File Backdoor: Typosquat → Poisoned Skill → Runtime Backdoor https://www.cyberhub.blog/article/28358-supply-chain-poisoned-rules-chain
Supply Chain & AI Rules File Backdoor: Typosquat → Poisoned Skill → Runtime Backdoor
Supply Chain & AI Rules File Backdoor — a two-flag CTF walkthrough chaining three real attack patterns. 1. A stray dev TODO comment on the OopsSec Store's /admin/documents page name-drops a typosquatted npm package (react-toastfy vs. react-toastify) and a "diag endpoint". 2. Using the app's known path-traversal bug (/api/files?file=..), you read the fake package's package.json and its postinstall script, which explains it *would* drop a poisoned Cursor rules file to ~/.cursor/rules/. 3. Flag #1 hides in that rules file (lab/quarantine/productivity-helper.mdc): an HTML-comment block — invisible in markdown previewers but read raw by the AI agent — instructs it to silently add an admin diag route with a magic-header auth bypass. 4. Flag #2: hitting /api/admin/diag with X-Debug-Auth: dbg_8f3a7c91e2b4d6a05e21 returns the flag, no real auth required. The chain mirrors real threats: npm typosquatting/maintainer takeovers, Pillar Security's 2025 "Rules File Backdoor," and hardcoded magic-header bypasses. Defenses: block/sandbox install scripts, treat AI rules files as reviewed code, grep them raw for hidden comments/unicode tricks, run SCA on every PR, and centralize auth so route-level bypasses are impossible by design.
www.cyberhub.blog
September 30, 2026 at 8:37 PM
Hackers Attack Python Developers by Poising With Typosquat on PyPI
Hackers Attack Python Developers by Poising With Typosquat on PyPI
An automated risk detection system identified a typosquatting campaign targeting popular Python libraries on PyPI.
cybersecuritynews.com
April 1, 2024 at 3:24 AM
Socket Researchers have discovered a backdoored typosquat package in the Go ecosystem, impersonating the widely used BoltDB database module, exploiting Go Module Proxy caching to persist undetected for years #Exploit #Golang
Go Supply Chain Attack: Malicious Package Exploits Go Module...
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.
socket.dev
February 12, 2025 at 8:05 AM
good luck trying to typosquat my DID
August 2, 2024 at 5:18 AM
can't you just typosquat the namespace instead? like fooo/barqux
September 25, 2025 at 9:45 AM
Popular Rust crates compromised:

Affected versions of arrayref, internment, and append-only-vec were modified to depend on proc-macro1, a malicious typosquat of proc-macro2. Its build script downloaded and executed malware during Cargo builds.

Analysis:
socket.dev/blog/popular...
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.
socket.dev
August 20, 2026 at 4:42 PM
Just another typosquat. So far all supply chain attacks I have seen in Go are of the form "this malicious module is malicious." I honestly wonder if MVS just makes compromising popular modules and worming unappealing, if the ecosystem has better practices, or if it just hasn't happened yet.
May 20, 2026 at 12:14 AM
haha this is diabolical

i also appreciated "typosquat-style packages such as rsquests, tlask, and rlask"
June 9, 2026 at 3:52 AM
It seams that typosquated packages where prepared to do some data exfiltration on developer systems on Crates.io. The packages where successful removed by the Crates.io team.
blog.phylum.io/rust-malware...

#Rust #phylum #typosquat #Malware #infosec #DataExfiltration
August 25, 2023 at 6:25 AM
This typosquat is all fancied up to look legit, seems like the threat actor put in a lot of effort here. We were once again impressed by how fast the crates.io team took it down! 👏

cc: @thisweekinrust.bsky.social @rustaceans.bsky.social @theembeddedrust.bsky.social @campuscodi.risky.biz
🚨 New Socket Threat Research: We found a malicious typosquat targeting Rust devs. The finch-rust crate mimics the legit finch crate but loads a credential-stealing payload and exfiltrates data to rust-docs-build[.]vercel[.]app.

Details + IOCs: socket.dev/blog/malicio... #Rustlang
Malicious Crate Mimicking ‘Finch’ Exfiltrates Credentials vi...
Socket found a Rust typosquat (finch-rust) that loads sha-rust to steal credentials, using impersonation and an unpinned dependency to auto-deliver up...
socket.dev
December 5, 2025 at 10:55 PM
Socket Security has discovered a malicious Go module for the BoltDB database that contains a hidden backdoor.

The module is cached in the Go Module Mirror, the first attack documented making it in the the Go Module Mirror despite manual code reviews.

socket.dev/blog/malicio...
Go Supply Chain Attack: Malicious Package Exploits Go Module...
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.
socket.dev
February 4, 2025 at 5:50 PM
I’m starting a new coding project called Domain Assassin, a tool to find typosquat domains easily. Both Dockerized & non-Dockerized builds, full rebuild of an old idea, made on my own time so I can open source it. #Cybersecurity #Dev
1/2
October 20, 2025 at 4:29 AM
Yeah, I like it too! the only reason I wish we'd come up with something better is it's impossible to say the URL out loud and have people type it correctly (we own the typosquat, but)
April 12, 2025 at 3:48 AM