Saturday 05 September 2026 04:02:37 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

WIKICROOK

Namespace hijacking

Using naming identity to confuse package ownership.

Namespace hijacking is a naming attack in software ecosystems where an attacker registers or publishes a package, extension, or account that matches, closely resembles, or exploits a trusted namespace. The goal is to confuse users about who owns the software and make a malicious item look legitimate. In package registries and extension stores, names, publishers, and organization paths are part of the trust model, so identity abuse can be as dangerous as code-level malware.

This matters because developers often install tools quickly and rely on familiar labels. A hijacked namespace can redirect attention away from a fake publisher, letting a malicious package land in build systems, CI environments, or developer workstations. Defenders look for mismatched publisher details, sudden lookalike registrations, unusual update patterns, and shared infrastructure such as common domains or servers. Strong verification, reserved namespaces, and manual review of high-trust packages help reduce this risk.

← WIKICROOK index