Typosquatting 2019 Incident #22

jeIlyfish / python3-dateutil

Estimated Financial Impact
SSH/GPG key theft
Blast Radius
Homoglyph attack; undetected ~1 year

What Happened

A capital "I" was substituted for a lowercase "l" in the package name jellyfish on PyPI, creating jeIlyfish. The package was live for approximately one year before detection. A companion package python3-dateutil imported the malicious code, resulting in SSH and GPG key theft.

✓

Risk Guard: Caught

PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCH

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
Socket Caught Typosquatting detection across ecosystems
Snyk Missed No typosquatting detection
Sonatype (Nexus) Caught Nexus Firewall typosquatting detection
Black Duck Missed No typosquatting detection
Endor Labs Missed No typosquatting detection
← crossenv typosquatting colourama →