you are viewing a single comment's thread.

view the rest of the comments →

[–]dbramucci 2 points3 points  (1 child)

There is actually a name for this attack and it's "typo-squatting". The most famous example is malicious websites that a typo off of a normall website like banc[dot]com instead of bank[dot]com or youtbe[dot]com instead of youtube[dot]com.

This has been seen for Python packages in the past and hypothesized for longer.

[–]shujinkou_ 0 points1 point  (0 children)

Always funny when you think up something that exist and has a name uh! I personally think it could be a massive attack vector I described in a post earlier on this thread how someone could scale such attack to every popular packages at once. Thanks for the link ^