#typosquatting
7 stories taggedtyposquatting.

Malicious RubyGems Packages Impersonate Popular Libraries to Steal Windows Credentials
Researchers flagged seven typosquatted gems on August 15, 2026, part of a wider campaign delivering a Windows information stealer.

77 fake developer tools on Open VSX quietly mapped coders' machines for a week
The counterfeit extensions copied real names from AMD, Azure, Salesforce and others, then phoned home to a domain registered days earlier.

Fake Newtonsoft.Json Package on NuGet Was Built to Rig Live Betting Games
A trojanised copy of a popular coding library targeted Digitain's gambling platform, quietly tampering with live game results.

Fake 7-Zip Downloads Are Quietly Turning Home PCs Into Criminal Middlemen
A group Infoblox calls Lurking Lizard has been running a rogue proxy service from 230+ lookalike sites since 2022, hiding the malware inside fake copies of the popular 7-Zip file compression tool.

Fake Rollup Helper Packages on npm Traced to North Korean Hackers
Two look-alike JavaScript packages copied a popular developer tool line-for-line, then quietly opened a back door onto the machines of anyone who installed them.

Three npm Packages Squat PostCSS Names to Drop a Windows RAT
Typosquatted utilities pulled roughly a thousand combined downloads before researchers flagged them. The payload targets Windows developer machines, which is exactly where the credentials live.

Typosquatted NuGet 'Sicoob.Sdk' Hoovers PFX Certs From Brazilian Banks
A poisoned package impersonating Brazil's Sicoob co-op banking network exfiltrates client IDs and PFX certificates — the same certs that sign API calls into the financial system.