Typosquatting 2017 Incident #21 CVE-2017-16074

crossenv typosquatting

Estimated Financial Impact
Minimal (~50 installs)
Blast Radius
Established npm typosquatting pattern

What Happened

User "hacktask" published ~40 npm packages with names mimicking popular packages (crossenv for cross-env, babelcli for babel-cli). The packages exfiltrated environment variables on install. This was the first large-scale documented typosquatting campaign on npm and established the attack pattern.

Sources: npm blog post

✓

Risk Guard: Caught

PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCH

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
Socket Caught Typosquatting detection across ecosystems
Snyk Missed No typosquatting detection
Sonatype (Nexus) Caught Nexus Firewall typosquatting detection
Black Duck Missed No typosquatting detection
Endor Labs Missed No typosquatting detection
← PyTorch torchtriton jeIlyfish / python3-dateutil →