Typosquatting 2024 Incident #24

500+ PyPI typosquatting campaign

Estimated Financial Impact
PyPI suspended all registrations
Blast Radius
zgRAT info-stealer; 800K users potentially affected

What Happened

An automated campaign deployed 566 malicious packages on PyPI in two waves, each containing an encrypted zgRAT info-stealer. PyPI was forced to temporarily suspend ALL new user registrations and project creation — an unprecedented action — with 800,000+ users potentially affected.

✓

Risk Guard: Caught

PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCHPACKAGE_INSTALL_SCRIPTS

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
Socket Caught Typosquatting detection across ecosystems
Snyk Missed No typosquatting detection
Sonatype (Nexus) Caught Nexus Firewall typosquatting detection
Black Duck Missed No typosquatting detection
Endor Labs Missed No typosquatting detection
← colourama 451-package PyPI crypto campaign →