Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

GCHQ Chief Urges Action as AI Reshapes Cyber Threats

May 28, 2026

Agent AI is Coming. Are You Ready?

May 28, 2026

Attackers Move Past Typosquatting to Realistic Package Impersonation

May 28, 2026
Facebook X (Twitter) Instagram
Friday, May 29
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Attackers Move Past Typosquatting to Realistic Package Impersonation
News

Attackers Move Past Typosquatting to Realistic Package Impersonation

Team-CWDBy Team-CWDMay 28, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Most malicious open source packages have moved beyond misspelling popular project names, instead disguising themselves as plausible plugins, configs and helpers that fit naturally into a developer’s workflow.

That is the central finding of new analysis by Sonatype, which examined 4309 malicious packages and found that 91% used naming-variant tactics rather than classic typosquatting. Only 9% depended on the spelling slips that traditional defenses are built to catch.

The shift matters because these packages are not harmless lookalikes. The most common behaviors were host and secrets exfiltration, followed by droppers and backdoors, turning a routine install into a route for credential theft and follow-on compromise.

Borrowing the Language of Real Code

Rather than copying a trusted name letter-for-letter, attackers now increasingly build names that look adjacent to a legitimate project.

Sonatype recorded suffix addition as the single most common tactic, accounting for 43.6% of cases, alongside prefixes, embedded target terms, dependency-confusion patterns and version mimicry.

Credit: Sonatype.

These names work because they feel routine. Developers expect popular frameworks to carry a long tail of plugins, software development kits (SDKs), wrappers and scoped modules, so terms like plugin, config and sdk rarely trigger suspicion, giving attackers room to hide multi-stage behavior in plain sight.

“Typosquatting is table stakes now,” said Brian Fox, CTO and co-founder of Sonatype. He added that attackers are copying the language, structure and habits of real software ecosystems, and that a malicious package may already sit on a developer machine by the time it has built a reputation.

Credit: Sonatype.
Credit: Sonatype.

Targeting Trusted Ecosystems

The activity clusters where adjacent packages are already common.

React was the most-targeted ecosystem with 540 malicious packages, ahead of the ESLint plugin and config ecosystem and Tailwind’s library of add-ons, with crypto and DeFi tooling also featuring heavily.

Read more on similar threats: Researchers Uncover 454,000+ Malicious Open Source Packages

Credit: Sonatype.
Credit: Sonatype.

Sonatype also pointed to evidence of industrialization, with the same naming tactics, infrastructure and identities reused across multiple package families rather than appearing as one-off attempts. Defenders, the cybersecurity vendor argued, should assess suspicious packages at the campaign and publisher levels, not one package at a time.

The takeaway for security teams is that typo detection and static reputation checks are no longer enough. Sonatype urged organizations to add friction for first-seen dependencies, scrutinize anything that looks framework-adjacent and weigh naming patterns and publisher behavior before a component enters the build.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleGitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos
Next Article Agent AI is Coming. Are You Ready?
Team-CWD
  • Website

Related Posts

News

GCHQ Chief Urges Action as AI Reshapes Cyber Threats

May 28, 2026
News

Agent AI is Coming. Are You Ready?

May 28, 2026
News

GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

May 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

Scams target soccer fans with fake World Cup tickets, merchandise

May 22, 2026

AI-powered financial scams swamp social media

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.