Q: A developer accidentally mistypes a Python package installing command as `pip install request` instead of `requests`. The installation succeeds, but the application begins acting strangely. What attack vector just occurred?
This is a software supply chain attack known as Typosquatting.
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
This is a software supply chain attack known as Typosquatting. Malicious actors purposefully publish packages to popular public repositories (PyPI, NPM, RubyGems) with names intentionally misspelled slightly differently than highly popular libraries (e.g., request vs requests, or react-dom vs reactdom). If a developer makes a typo, they inadvertently download and execute the attacker's malicious code directly inside the corporate network. Mitigation: Enforce the use of a private, curated internal artifact repository (like Artifactory or Nexus) that caches approved public packages, preventing developers from pulling arbitrary unvetted code directly from the public internet.
- Immediate Triage: This is a software supply chain attack known as Typosquatting.
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.