User "hacktask" published ~40 npm packages with names mimicking popular packages (crossenv for cross-env, babelcli for babel-cli). The packages exfiltrated environment variables on install. This was the first large-scale documented typosquatting campaign on npm and established the attack pattern.
Sources: npm blog post
PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package |
| Socket | Caught | Typosquatting detection across ecosystems |
| Snyk | Missed | No typosquatting detection |
| Sonatype (Nexus) | Caught | Nexus Firewall typosquatting detection |
| Black Duck | Missed | No typosquatting detection |
| Endor Labs | Missed | No typosquatting detection |