Typosquatting attacks developer attention
A package named almost like the one you wanted, published deliberately, relying on somebody typing quickly.
It requires no technical sophistication at all and works because installing a dependency is a routine action performed dozens of times a day. The defence is largely mechanical: allow-listed sources, review of new dependencies, and tooling that flags a first-time package rather than trusting anybody to read carefully every time.
More on Software supply chain
- A trusted build can faithfully ship malicious sourceThe oven never reads the recipe
- Dependency confusion exploits naming and resolutionSame name, wrong shelf
- Lockfiles improve repeatability, not eternal safetyAlways the same tin
- Transitive dependencies enlarge unseen trustOne handshake, a hundred guests
- Maintainer compromise can use the normal release channelIt came by the usual van
- Build secrets should not become build artefactsDeleted on top, still underneath
