Typosquatting 2022 Incident #33

241 cryptominer typosquats

Estimated Financial Impact
Cryptomining losses
Blast Radius
React, argparse, AIOHTTP targets

What Happened

241+ malicious packages typosquatting React, argparse, and AIOHTTP published across npm and PyPI. Each downloaded Bash scripts on Linux to execute XMRig Monero miners.

✓

Risk Guard: Caught

PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCH

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
Socket Caught Typosquatting detection across ecosystems
Snyk Missed No typosquatting detection
Sonatype (Nexus) Caught Nexus Firewall typosquatting detection
Black Duck Missed No typosquatting detection
Endor Labs Missed No typosquatting detection
← MUT-8694 cross-ecosystem W4SP Stealer campaign →