Typosquatting 2023 Incident #25

451-package PyPI crypto campaign

Estimated Financial Impact
Crypto clipboard theft
Blast Radius
451 packages in ~1 hour

What Happened

451 typosquatted packages were published to PyPI in approximately one hour, targeting beautifulsoup, selenium, and pytorch. Each contained clipboard-replacing malware that swapped cryptocurrency wallet addresses during transactions.

✓

Risk Guard: Caught

PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCH

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
Socket Caught Typosquatting detection across ecosystems
Snyk Missed No typosquatting detection
Sonatype (Nexus) Caught Nexus Firewall typosquatting detection
Black Duck Missed No typosquatting detection
Endor Labs Missed No typosquatting detection
← 500+ PyPI typosquatting campaign npm 287-package blockchain C2 →