Attackers Move Past Typosquatting to Realistic Package Impersonation

2026-05-28T20:52:20Z937c39803e31f1693e670c452bd2ca73548a7bf23f77a1f74ae3ef1860575d42
AI risk','agentic AI','LLM manipulation','zero‑day disclosure','Android RATBTMOBGitHub breachGlasswormGrafanaJinx‑0164Kali365Nimbus ManticoreOAuth token theftPureLogsSEO poisoningTanStackVS Code extensionWebwormbotnetinfostealernpmnpm wormpackage impersonationphishingsoftware supply chainstate‑linked actorssupply chaintyposquatting

What happened

Recent Infosecurity Magazine reporting highlights an escalation in software supply‑chain and phishing threats: attackers increasingly impersonate real open‑source packages and IDE extensions instead of relying on typosquatting, leading to widespread compromises (npm Mini Shai‑Hulud, malicious VS Code/Nx Console extension, Grafana/TanStack breach, GitHub internal repo access). Simultaneously, diverse malware and phishing campaigns (Glassworm botnet, BTMOB Android RAT, PureLogs, Kali365 OAuth‑token phishing, SEO‑poisoning infostealers) and state‑linked actors (Webworm, Nimbus Manticore, Jinx‑016

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
937c39803e31f1693e670c452bd2ca73548a7bf23f77a1f74ae3ef1860575d42
Enrichment time
2026-05-28T20:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Attackers Move Past Typosquatting to Realistic Package Impersonation · Baitaphish