Typosquatting 2024 Incident #30

@typescript_eslinter scope spoof

Estimated Financial Impact
Hundreds of daily downloads
Blast Radius
Namespace/scope spoofing

What Happened

A fake scoped npm package @typescript_eslinter/eslint mimicked the legitimate @typescript-eslint, exploiting the visual similarity between scoped and unscoped package names. Both were receiving hundreds of downloads daily before detection.

✓

Risk Guard: Caught

PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCH

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
Socket Caught Typosquatting detection across ecosystems
Snyk Missed No typosquatting detection
Sonatype (Nexus) Caught Nexus Firewall typosquatting detection
Black Duck Missed No typosquatting detection
Endor Labs Missed No typosquatting detection
← Maven Jackson typosquat NuGet malware campaigns →