One-Third of npm Typo Package Names Are Confirmed Malicious, Study Finds
A live audit of typosquatting exposure across npm and PyPI checked every single-character variation — omissions, duplications, and adjacent transpositions — of the 30 most popular packages on each registry. On npm, 297 of 498 typo-variant names are currently registered, and 97 of those carry confirmed malicious advisories in OSV's public database. PyPI showed far lower risk, with only 47 of 582 candidate names registered and none flagged as malicious. The npm package 'request', though deprecated since 2020, topped the list with 17 confirmed-malicious typo variants, reflecting the lingering danger of widely depended-upon legacy packages. The findings, based on live API queries conducted on 25 August 2026, highlight a significant and documented supply-chain threat in the npm ecosystem.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in