Definition
Typosquatting is publishing a malicious package (or registering a domain) under a name that is one slip of the keyboard away from a popular one, so that people who mistype the name install the attacker's code instead.
How package typosquatting works
Package registries are first come, first served: anyone can publish any free name. An attacker picks a popular package and registers names that people plausibly type by accident:
- Transposed or doubled letters:
expres,lodahs,reqeusts - Swapped separators:
cross-envvscrossenv,python-dateutilvspython3-dateutil - Look-alike characters: a capital
Ifor a lowercasel, as injeIlyfish - Plausible suffixes:
-js,-node,-utils,-dev
The squatted package usually re-exports the real one so nothing visibly breaks, and adds a small payload, most often in a postinstall script, that reads environment variables, ~/.npmrc, SSH keys or cloud credentials and posts them to a remote server.
Real examples
- crossenv (npm, 2017): a copy of
cross-envthat sent the installer's environment variables, including npm tokens, to the attacker. It was one of about 40 typosquats from the same account. - jeIlyfish and python3-dateutil (PyPI, 2019): look-alikes of
jellyfishandpython-dateutilthat stole SSH and GPG keys. - Registries now remove thousands of typosquats a year; most live only hours or days, which is long enough for CI pipelines and copy-pasted install commands.
How to protect against typosquatting
- Install from a lockfile (
npm ci,pip install --require-hashes) so a typo in a one-off command cannot silently enter the tree. - Review every new direct dependency in code review: name, weekly downloads, repository link and publish date.
- Block or review install scripts:
npm ci --ignore-scripts, or a package manager that only runs scripts for allow-listed packages. - Scan new and changed packages before they reach developer machines or CI. Togoder Security reads each package's source and flags credential theft and exfiltration even when the name looks legitimate.
Frequently asked questions
Is typosquatting illegal?
Registering a similar name is not illegal in itself, but publishing a package that steals credentials is computer misuse in most jurisdictions, and every major registry bans it and removes such packages.
Does npm block typosquats?
npm rejects some names that differ from existing packages only by punctuation (for example cross-env vs crossenv for new publishes) and removes reported malware, but it cannot catch every look-alike, so typosquats still appear regularly.
Can npm audit detect typosquatting?
Only after a malicious package has been reported and an advisory published. A typosquat published today passes npm audit; source-code scanning is what catches the payload.