Malicious open-source packages adopt realistic naming tactics over typosquatting (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- 91% of 4,309 malicious packages used naming variants, not typosquatting.
- Suffix addition was the most common tactic at 43.6%.
- Most targeted ecosystems: React (540 packages), ESLint, Tailwind.
- Sonatype recommends campaign-level and publisher-level analysis.
"Sonatype analyzed 4,309 malicious open-source packages and found that 91% use naming variants rather than classic typosquatting. The most common tactic is suffix addition (43.6%). Targeted ecosystems include React (540 packages), ESLint, and Tailwind. These packages exfiltrate host data and secrets, or install droppers and backdoors. Sonatype recommends assessing packages at the campaign and publisher level."
#malicious packages
#supply chain attacks
#naming variants
no comments yet.