Typosquatting 2024 Incident #26

npm 287-package blockchain C2

Estimated Financial Impact
Multi-platform malware
Blast Radius
Ethereum smart contracts for C2; novel takedown resistance

What Happened

287 malicious npm packages impersonated Puppeteer, Bignum.js, and crypto libraries. Notable for using Ethereum smart contracts for command-and-control communication, making traditional takedowns nearly impossible since the C2 infrastructure is decentralized and censorship-resistant.

✓

Risk Guard: Caught

PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCH

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
Sonatype (Nexus) Partial Weaker ecosystem coverage
Socket Caught Typosquatting detection across ecosystems
Snyk Missed No typosquatting detection
Black Duck Missed No typosquatting detection
Endor Labs Missed No typosquatting detection
← 451-package PyPI crypto campaign rustdecimal / CrateDepression →