الأحد 26 يوليو 2026 22:54:17 GMT+02:00

Netcrook

الرئيسيةالبيان
الأخبار
Techcrook
Geocrook
WikicrookالفريقAppاتصالتسجيل الدخول
EnglishItaliano

#Typosquatting


A Fake Json Library, a Hidden Betting Hook, and a Log-Shaped Exit

Published: 22 July 2026 10:06Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A trojanized NuGet package reportedly masqueraded as Newtonsoft.Json, stayed useful for ordinary .NET apps, and only turned hostile inside a betting backend where integrity mattered most.

When AI Invents a Domain, Attackers Can Buy the Lie

Published: 01 July 2026 12:49Category: Cyber Intelligence & Threat TrendsAuthor: PHANTOMINTEGRITY

A newly named phishing tactic turns hallucinated URLs into real infrastructure, giving criminals a fresh path to impersonate brands and stage malware delivery.

PyPI Poisoning Hits Telegram Bot Builders, and the Backdoor Hides in Plain Sight

Published: 01 July 2026 02:08Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A malicious package campaign tied to Telegram bot development shows how a trusted Python repository can become the delivery layer for server-side compromise.

The Browser Add-on That Turned Search Into a Trap

Published: 30 June 2026 08:09Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A Chromium extension posing as an AI search helper shows how browser trust can be bent with branding, redirect rules, and page-level scripting.

When a Skill Store Turns Hostile: The ClawHub Poisoning Case

Published: 29 June 2026 14:28Category: CybercrimeAuthor: CRYSTALPROXY

A compromised AI extension marketplace shows how trust, rankings, and package names can be turned into a delivery system for hostile code.

Fake PostCSS Packages Turned a Routine npm Install into a Windows RAT Risk

Published: 24 June 2026 10:44Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

Three lookalike npm packages aimed at frontend developers underscore how package-name trust and installer-time execution can collide on a developer workstation.

Lookalike npm Packages Turn a CSS Search into a Supply-Chain Trap

Published: 23 June 2026 12:19Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A small cluster of PostCSS-themed npm packages shows how name confusion and install-time trust can turn routine dependency work into a Windows malware risk.

A Lookalike npm Name, Then a Windows Script Chain: The Supply-Chain Trap Behind a RAT Drop

Published: 22 June 2026 14:52Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A typosquatted package in the npm ecosystem shows how a single confusing name can hand attackers a path from dependency install to Windows-native execution.

A Lookalike npm Package Turned a Trusted CSS Name Into a Windows Malware Pipe

Published: 22 June 2026 14:07Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A deceptive package name in the PostCSS orbit shows how open-source trust can be abused before any code ever reaches production.

When a Bank Lookalike Becomes an Execution Trap

Published: 18 June 2026 10:05Category: Malware & BotnetsGeo: South America / BrazilAuthor: NEXUSGUARDIAN

Typosquatted domains, AI-built lure pages, and a ClickFix prompt can turn a routine web visit into PowerShell execution and a banking trojan dropper.

Namespace Trust Broke First: The npm Supply Chain Story Hidden Inside Mastra

Published: 17 June 2026 17:17Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

More than 140 packages in the Mastra namespace were reported as part of a supply-chain compromise, with a typosquatting dependency, easy-day-js, used in a way that could fit install-time malware delivery.

npm Typosquatting Turns Package Installs Into a Wallet Risk

Published: 12 June 2026 14:34Category: CybercrimeGeo: North America / USAAuthor: VULNCRUSADER

Malicious lookalike packages in the npm ecosystem can turn routine dependency installs into a supply-chain execution event for Web3 teams and crypto wallet operators.

Typosquatted Packages Turn Trusted Dev Tooling Into a Secret-Harvesting Path

Published: 12 June 2026 08:12Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A Solana-themed package campaign shows how npm and PyPI installs can become a delivery route for code that runs before a developer ever opens the library.

The World Cup’s Hidden Arena: Malicious Domains Ahead of the Spotlight

Published: 11 June 2026 18:26Category: Cyber Intelligence & Threat TrendsGeo: Europe / SwitzerlandAuthor: GHOSTCOMPLY

Researchers warn that the tournament is already surrounded by thousands of malicious domains, turning a global sports moment into a high-value impersonation target.

World Cup Fever, Scam Fuel: The Fraud Playbook Moving in Before Kickoff

Published: 08 June 2026 12:58Category: Security Awareness & Social EngineeringAuthor: PATCHKNIGHT

As attention builds around the 2026 FIFA World Cup, spoofed sites, phishing lures, and fake storefronts are turning fan excitement into a ready-made fraud channel.

Big Reveal Nights Create Small Windows for Big Lies

Published: 06 June 2026 12:09Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

A two-hour showcase packed with more than 20 game announcements is a reminder that live entertainment events are also trust events, where speed can outpace verification.

PyPI’s Newest Lookalike: How a Single Package Name Can Turn a Registry Into a Trap

Published: 05 June 2026 15:19Category: CybercrimeGeo: North America / USAAuthor: CRYSTALPROXY

A malicious project on Python’s main package index shows why trust in open-source software now starts with name verification, not just reputation.

One Letter, One Registry, One Dangerous Copycat Package

Published: 05 June 2026 10:41Category: CybercrimeGeo: North America / USAAuthor: VULNCRUSADER

A PyPI typosquat built to resemble the parsimonious parser library shows how easily trusted package names can be turned into bait for developers.

World Cup Fever Is Already Being Weaponized by Fake FIFA Sites and Banking-Malware Lures

Published: 05 June 2026 10:18Category: Security Awareness & Social EngineeringGeo: Europe / SwitzerlandAuthor: PATCHKNIGHT

With the tournament window approaching, attackers are pairing typosquatted domains, cloned login pages, and deceptive streaming apps to turn fan excitement into credential theft and financial fraud.

FIFA-Impersonation Domains Turn Fan Excitement Into a Phishing Trap

Published: 01 June 2026 02:05Category: Security Awareness & Social EngineeringGeo: Europe / SwitzerlandAuthor: PATCHKNIGHT

A reported campaign tied to GHOST STADIUM used fraudulent web domains to mimic FIFA’s login experience and seek credentials and payment-related data, showing how brand trust becomes attack surface.