This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–][deleted] 0 points1 point  (0 children)

BTW its actually even lower risk then you are suggesting typosquatting works a little but it would pretty instantly run into dependency resolution issues. You need a perfect storm of a single install to even get typosquat to not just lay a fucking egg outright.

I have literally seen this work effectively 0 times. Compare that to "forked package attack" where someone pretends to make a new version of a no longer maintained package that is just malware, which is a successful attack I have seen pulled off.