Skip to main content

Threats Tagged 'typosquatting'

View all threats tagged with 'typosquatting'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: typosquatting

Threats Tagged 'typosquatting'

Click on any threat for detailed analysis and mitigation recommendations

Cybercriminals have created numerous fake websites mimicking Bitrefill, a legitimate cryptocurrency-based gift card and eSIM retailer. These fraudulent sites appear in search engine results and use lookalike domains incorporating the Bitrefill brand name with added words or character substitutions, including internationalized domain names using Punycode. Victims are guided through convincing checkout processes that replicate Bitrefill's legitimate payment flow, complete with cryptocurrency options, QR codes, and countdown timers. However, payments are sent directly to attacker-controlled cryptocurrency addresses rather than Bitrefill, with virtually no chance of recovery. The operation demonstrates sophisticated measurement using commercial analytics software to optimize conversion rates, indicating organized criminal activity rather than opportunistic fraud.

Join the discussion
0

A phishing campaign abuses npm package mirrors to host fake Cloudflare Captcha pages embedded in malicious npm packages. These pages are served via trusted mirror domains, increasing their credibility and facilitating phishing attacks such as ClickFix delivery. The campaign uses typosquatted domains and legitimate key-value storage services to redirect victims dynamically. Downloading the packages is not harmful, but accessing the HTML files through mirror URLs exposes users to phishing risks.

Join the discussion

On August 20, 2026, malicious versions of three Rust crates ([email protected], [email protected], and [email protected]) were published to crates.io. These crates included a typosquatted dependency named proc-macro1, whose build script downloads and executes a remote binary during compilation. This binary installs a backdoor that communicates with command and control servers over HTTPS, exfiltrates host and browser data, enumerates installed applications, and persists via common OS mechanisms such as Registry Run keys, LaunchAgents, or systemd user services. The attack infrastructure overlaps with North Korean threat actor operations, notably the Mastra campaign and previous DPRK-linked supply chain attacks. No official remediation guidance is currently available.

Join the discussion

A supply chain attack targeted three popular Rust crates (arrayref, internment, and append-only-vec) by injecting a malicious typosquatted dependency named proc-macro1. This malicious package executed malware during Cargo builds across Linux, macOS, and Windows platforms, delivering backdoors that profiled victims, stole browser data, maintained persistence, and enabled remote command execution. The attack threatened developer workstations, CI/CD pipelines, and release infrastructure. The Rust Security Response Team removed the malicious releases and locked the maintainer's account to mitigate the threat.

Join the discussion

BRIDGEHEAD is a supply-chain typosquatting campaign discovered in August 2026 that distributed 40 malicious npm packages impersonating popular libraries such as chalk, axios, and lodash. These packages contained install scripts that detect Windows or Windows Subsystem for Linux (WSL) environments and download a 22MB Rust-based executable from GitHub. The payload executes entirely in memory without writing files to disk and targets cryptocurrency wallets, browser credentials, cookies, and Telegram sessions. The campaign leverages legitimate services for reconnaissance and data exfiltration, complicating detection and takedown efforts. Although the malicious npm packages were removed within 84 minutes, the GitHub-hosted payload remained active for 39 hours, and the command-and-control server continued operating. This campaign specifically targets developers using WSL by crossing from Linux environments into Windows systems.

Join the discussion

A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

Join the discussion

A fraudulent website impersonating Corepack, the Node.js package manager tool, is distributing malware to developers. The attackers exploit timing around Corepack's removal from Node.js bundling, targeting developers searching for installation instructions. The site offers Windows executables that deliver OpenShield infostealer and proxyware, enrolling victim machines in bandwidth-sharing networks without consent. The payload steals browser credentials, SSH keys, establishes persistence, and routes third-party traffic through compromised systems. An alternative download path delivers adware and trojan components disguised as OperaGX installer. The site features AI-generated content with obvious errors, including confusing Yarn package manager with textile crafts. The domain has been reported to registrars for takedown after community members identified the threat.

Join the discussion

Socket's AI scanner identified 17 malicious packages across npm and PyPI ecosystems published simultaneously on July 7, 2026. The packages typosquatted legitimate PaySafe, Skrill, and Neteller payment SDK names to steal developer credentials and tokens. The malware implements sophisticated anti-analysis techniques including sandbox detection based on CPU cores and hostname patterns, multi-layer C2 domain obfuscation using XOR encoding, and selective activation gating. Upon execution, the packages exfiltrate environment variables containing API keys, secrets, tokens, and authentication credentials to AWS-hosted infrastructure via an ngrok endpoint. The campaign demonstrates coordinated cross-ecosystem capabilities, proper operational security through varied obfuscation keys, and knowledge of defender technologies, suggesting an organized threat actor with financial motivation.

Join the discussion

AI agents are increasingly vulnerable to indirect prompt injection (IPI) attacks, where malicious instructions are embedded in web content to manipulate AI-driven workflows. Two campaigns were identified that combine SEO poisoning with CSS/HTML abuse to influence AI decision-making. The first campaign uses fake API documentation to trick AI agents into making fraudulent payments for a fake Python library, incorporating hidden instructions in JSON-LD and CSS-concealed content directing payment of $3.00 via Stripe or approximately 0.0012 ETH to attacker wallets. The second campaign employs typosquatting to impersonate DeBank, a cryptocurrency portfolio tracker, embedding hidden prompts to make the fraudulent site appear as an authoritative source. Testing across 26 LLMs revealed 4 models were vulnerable to the payment scam and 2 models misclassified the typosquatting site, demonstrating measurable real-world impact.

Join the discussion

A massive campaign distributes malicious installer archives hosted on spoofed websites masquerading as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam. Over 90 domain names localized across 10 languages were discovered. The malicious archives bundle a legitimate Microsoft-signed install.exe binary with a rogue install.res.1033.dll library deployed via DLL sideloading. This installs the ScreenConnect remote access service, which then deploys AsyncRAT payloads through PowerShell and VBS scripts. The threat actors leverage SEO techniques to position fraudulent sites at the top of search engine results, targeting both individual users and corporate networks. The infrastructure spans three IP addresses with domains registered between October 2025 and March 2026, creating a global footprint with multi-language support.

Join the discussion

Showing 1 to 10 of 44 results

Filters:Tag: typosquatting
Page 1 of 5
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses