Mmastodon TechnologyCybersecurity first seen 4 h ago, last 4 h ago, peak #6
85 malicious npm packages found in typosquatting campaign
Original: (cloudsek.com) Automated Typosquatting Attack on npm Registry: 85 Malicious Packages Target Popular Libraries via Scoped
Cybersecurity firm CloudSEK reports an automated typosquatting campaign on the npm registry, with 85 malicious packages published under the @prime0 scope to impersonate popular libraries and trick developers into installing them. The packages target widely used open-source dependencies, raising concerns about supply chain security and the ease of automating fake package publication at scale.
Why now: Supply chain attacks on npm keep hitting developers, and this campaign shows how easily automation can scale malicious package publication.
Rank over time, top of the chart is #1. 2 snapshots from 4 h ago to 4 h ago.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/356460