Software Engineering KB

Home

❯

08 Security

❯

04 Supply Chain Security

❯

01 Concept

❯

Typosquatting

Typosquatting

Feb 10, 20261 min read

  • supply-chain-security
  • typosquatting

Typosquatting

← Back to Software Supply Chain

Publishing malicious packages with names similar to popular packages (e.g., “lodas” instead of “lodash”) on public registries. Developers who mistype package names or are inattentive during installation may inadvertently install malicious code.

Key Properties

  • Name Similarity Attacks
  • Registry Protection
  • Package Verification

supply-chain-security typosquatting


Graph View

  • Typosquatting
  • Key Properties

Backlinks

  • Software Supply Chain

Created with Quartz v4.5.2 © 2026

  • GitHub