Tag

#typosquatting

7 stories taggedtyposquatting.

An office worker at a desk during a phone call, a fake login page displayed on their monitor screen, with a hand reaching toward the keyboard about to enter cre
Threat Intelligence

The Fake IT Call and the Click That Opens the Door

Attackers are skipping the smash-and-grab, choosing polite phone calls, spoofed login pages and poisoned software guides to walk in through the front door.

4 min read
A software repository package listing showing nearly identical library names with subtle misspellings, with one package highlighted as malicious and credential-
Threat Intelligence

Malicious RubyGems Packages Impersonate Popular Libraries to Steal Windows Credentials

Researchers flagged seven typosquatted gems on August 15, 2026, part of a wider campaign delivering a Windows information stealer.

3 min read
A developer's computer monitor displaying code in an IDE, with network activity indicators and connection logs visible on the screen, suggesting background data
Threat Intelligence

77 fake developer tools on Open VSX quietly mapped coders' machines for a week

The counterfeit extensions copied real names from AMD, Azure, Salesforce and others, then phoned home to a domain registered days earlier.

4 min read
Illustration: a dimly lit developer workstation at night
Threat Intelligence

Fake Newtonsoft.Json Package on NuGet Was Built to Rig Live Betting Games

A trojanised copy of a popular coding library targeted Digitain's gambling platform, quietly tampering with live game results.

3 min read
Illustration: a modern home desk with an open laptop showing a generic software installer progress bar, a coffee mug
Threat Intelligence

Fake 7-Zip Downloads Are Quietly Turning Home PCs Into Criminal Middlemen

A group Infoblox calls Lurking Lizard has been running a rogue proxy service from more than 230 lookalike sites since 2022, hiding the malware inside fake copies of the popular 7-Zip file compression tool.

3 min read
Illustration for the story: Fake Rollup Helper Packages on npm Traced to North Korean Hackers
Threat Intelligence

Fake Rollup Helper Packages on npm Traced to North Korean Hackers

Two look-alike JavaScript packages copied a popular developer tool line-for-line, then quietly opened a back door onto the machines of anyone who installed them.

3 min read
Illustration: a cluttered developer desk at night, mechanical keyboard glowing amber
Threat Intelligence

Three npm Packages Squat PostCSS Names to Drop a Windows RAT

Typosquatted utilities pulled roughly a thousand combined downloads before researchers flagged them. The payload targets Windows developer machines, which is exactly where the credentials live.

2 min read
© 2026 Threat Vectr