Mastodon Mastodon Mastodon Mastodon

Typosquatting

Updated: · CyberSecureFox Editorial Team

Typosquatting is the registration of domain names or software package names that differ from popular ones by a small typo, in order to catch users who mistype or misread them.

How typosquatting works

Attackers register names that look almost right: a missing or doubled letter (gooogle.com), swapped characters, a different top-level domain (.co instead of .com), a hyphen or an extra word (“combosquatting”, such as paypal-secure-login.com). Homoglyph attacks go further and use characters from other alphabets – a Cyrillic “а” instead of a Latin “a” – so that the address looks identical.

The fake domain then hosts a phishing page, serves malware, collects mistyped emails or simply shows ads. Lookalike domains are also a key ingredient of email spoofing and business email compromise.

Typosquatting in software repositories

The same trick works in package managers. In 2017 npm removed “crossenv”, a typosquat of the popular “cross-env” package that stole environment variables, together with dozens of similar packages. Since then malicious typosquats appear on npm, PyPI and other registries every week; one mistyped install command is enough to run attacker code on a developer machine or in a build pipeline, turning typosquatting into a supply chain attack.

Why it works

Typosquatting relies on social engineering and simple human error: people type fast, read quickly and trust familiar names, especially on mobile screens where the full address is hidden.

How to protect yourself

  • Use bookmarks or a password manager, which only fills credentials on the real domain.
  • Companies should register common misspellings of their brand and monitor new domains and certificate transparency logs.
  • Developers should pin dependencies with lockfiles, check package names and download counts, and use registry scanning tools.
Synonyms:
URL hijacking