How a Single Keystroke Became an Attack Vector
Typosquatting — the publication of a malicious package under a name that differs by one or two characters from a legitimate, widely-used package — has produced some of the most consistently documented supply-chain campaigns across npm and PyPI. The targets are not exotic dependencies. They are the packages developers install from muscle memory.
PyPI saw one of the earliest well-catalogued waves in 2017, when researcher Nick Sweeting published a proof-of-concept package named urllib2 to demonstrate how easily the pattern worked. The registry removed it, but the demonstration landed: Nikolai Tschacher's 2016 undergraduate thesis had already shown that typosquatted packages on PyPI and npm were installed by real users in significant numbers.
The campaigns that followed were not proofs of concept. In 2018, a package named colourama — one letter off from the popular colorama — was found on PyPI collecting Bitcoin wallet addresses and redirecting clipboard contents on Windows machines. In 2017, npm's registry contained crossenv, mimicking the legitimate cross-env package maintained at the time with millions of weekly downloads; it exfiltrated environment variables, including credentials and API tokens, from the installing machine. npm removed dozens of packages in that single sweep.
The pattern accelerated. In 2021, security firm Sonatype identified packages on PyPI that imitated python-dateutil and variants of requests that dropped reverse shells. JFrog's security research team has tracked recurring campaigns targeting both registries throughout 2022 and 2023, repeatedly finding credential harvesters disguised as minor spelling variants of boto3, setuptools, and Pillow.
Registry responses have been reactive rather than structural. PyPI introduced mandatory two-factor authentication for critical package maintainers in 2023, and the PyPI security key grants programme distributed hardware keys to high-volume maintainers. npm, under GitHub's ownership since 2020, added automated malware scanning and tightened the threshold for package-name similarity checks. Neither registry has implemented mandatory provenance attestation for new packages as a blocking control, though Sigstore-based provenance support has since become available on PyPI.

The structural problem is indexing speed: both registries allow immediate publication, which means a campaign package can collect installs for hours before a human report triggers review. Researchers at Checkmarx documented in 2023 that some malicious packages on PyPI accumulated more than five thousand downloads before removal — enough to seed a credential-harvesting operation across a meaningful slice of an organisation's development environment.
The economics favour the attacker. Publication is free, the namespace is vast, and the window between upload and takedown has, historically, been measured in hours rather than minutes.
