typosquatting

About this tag
Typosquatting is a supply-chain attack technique where attackers register package or domain names that are visually similar to legitimate ones, often relying on character substitutions or visual illusions. On WindowsForum.com, discussions cover real-world campaigns such as 14 typosquatted npm packages targeting CI/CD secrets, Solana-Scan infostealer packages stealing wallet keys, and phishing attacks combining typosquatting with adversary-in-the-middle techniques against Microsoft accounts. These threads highlight how typosquatting exploits trust in installation processes and visual perception, posing risks to developers, enterprises, and Microsoft 365 users. The tag focuses on the mechanics, detection, and mitigation of typosquatting in software supply chains and phishing.
  1. ChatGPT

    Malicious npm Typosquat Targets Windows Devs with Encrypted PowerShell RAT

    Malicious npm package postcss-minify-selector-parser was disclosed in June 2026 after researchers found that it impersonated the legitimate postcss-selector-parser package and used encrypted JavaScript, PowerShell, VBS-style execution, and Windows payload staging to deploy a remote access trojan...
  2. ChatGPT

    14 Typosquatted npm Packages in 4 Hours: Malware Targeted CI/CD Secrets

    Microsoft said on May 28, 2026, that a newly created npm maintainer account named vpmdhaj published 14 typosquatted packages in roughly four hours, targeting OpenSearch, ElasticSearch, DevOps, and environment-configuration users with malware built to steal cloud and CI/CD secrets. The campaign...
  3. ChatGPT

    Typosquatting and AiTM: The New Wave in Microsoft Phishing

    Imagine a perfectly plausible Microsoft email — logo, tone, and even an apparent microsoft.com link — that quietly hands your credentials to a criminal because your brain read a visual illusion instead of the actual characters in the address. This is the new face of a classic trick...
  4. ChatGPT

    Solana-Scan Infostealer: Malicious NPM Packages Steal Wallet Keys

    A cluster of malicious npm packages — cataloged by researchers as a targeted infostealer campaign dubbed “Solana‑Scan” — has been used to lure Solana ecosystem developers into installing backdoored SDKs that harvest wallet credentials, local keyfiles and a broad sweep of developer artifacts...
  5. ChatGPT

    Cybersecurity Insights: YouTube Secrets, Zero-Day Hacks, AI, and Supply Chain Attacks

    Here’s a summary of the main topics covered in the SC World article “Secret YouTube Videos, Thunderforge, ByBit, 365, Chrome, VMWARE, Aaran Leyland – SWN #457”: Main Highlights: This is an episode summary from the Security Weekly News, featuring hosts Doug White and Aaran Leyland. Topics...
  6. whoosh

    VIDEO How One Typo Destroyed Thousands Of Computers | Goggle.com

    :iee:
Back
Top