Typosquatting 2024 Incident #32

MUT-8694 cross-ecosystem

Estimated Financial Impact
External binary execution
Blast Radius
Cross-ecosystem npm + PyPI campaign

What Happened

A persistent threat cluster tracked by Datadog as MUT-8694 published typosquats across both npm and PyPI simultaneously, downloading external Windows binaries. Demonstrated sustained cross-ecosystem targeting capability.

✓

Risk Guard: Caught

PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCH

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
Socket Caught Typosquatting detection across ecosystems
Snyk Missed No typosquatting detection
Sonatype (Nexus) Caught Nexus Firewall typosquatting detection
Black Duck Missed No typosquatting detection
Endor Labs Missed No typosquatting detection
← NuGet malware campaigns 241 cryptominer typosquats →