MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #6

85 malicious npm packages found in typosquatting campaign

Original: (cloudsek.com) Automated Typosquatting Attack on npm Registry: 85 Malicious Packages Target Popular Libraries via Scoped

Cybersecurity firm CloudSEK reports an automated typosquatting campaign on the npm registry, with 85 malicious packages published under the @prime0 scope to impersonate popular libraries and trick developers into installing them. The packages target widely used open-source dependencies, raising concerns about supply chain security and the ease of automating fake package publication at scale.

Why now: Supply chain attacks on npm keep hitting developers, and this campaign shows how easily automation can scale malicious package publication.

npmCloudSEK@prime0

Open on mastodon →

Rank over time, top of the chart is #1. 2 snapshots from 10 h ago to 10 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/356460