Attackers Move Past Typosquatting to Realistic Package Impersonation
2026-05-28T20:52:20Z•937c39803e31f1693e670c452bd2ca73548a7bf23f77a1f74ae3ef1860575d42
AI risk','agentic AI','LLM manipulation','zero‑day disclosure','Android RATBTMOBGitHub breachGlasswormGrafanaJinx‑0164Kali365Nimbus ManticoreOAuth token theftPureLogsSEO poisoningTanStackVS Code extensionWebwormbotnetinfostealernpmnpm wormpackage impersonationphishingsoftware supply chainstate‑linked actorssupply chaintyposquatting
What happened
Recent Infosecurity Magazine reporting highlights an escalation in software supply‑chain and phishing threats: attackers increasingly impersonate real open‑source packages and IDE extensions instead of relying on typosquatting, leading to widespread compromises (npm Mini Shai‑Hulud, malicious VS Code/Nx Console extension, Grafana/TanStack breach, GitHub internal repo access). Simultaneously, diverse malware and phishing campaigns (Glassworm botnet, BTMOB Android RAT, PureLogs, Kali365 OAuth‑token phishing, SEO‑poisoning infostealers) and state‑linked actors (Webworm, Nimbus Manticore, Jinx‑016
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 937c39803e31f1693e670c452bd2ca73548a7bf23f77a1f74ae3ef1860575d42
- Enrichment time
- 2026-05-28T20:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.