Typosquatting attacks developer attention

A package named almost like the one you wanted, published deliberately, relying on somebody typing quickly.

It requires no technical sophistication at all and works because installing a dependency is a routine action performed dozens of times a day. The defence is largely mechanical: allow-listed sources, review of new dependencies, and tooling that flags a first-time package rather than trusting anybody to read carefully every time.

More on Software supply chain