Typo-squatting uses a lookalike package name to trick users into installing a malicious package, while repojacking abuses abandoned or renamed repository namespaces so attackers can attach malicious code to a trusted project name. Both rely on trust signals, but typo-squatting targets human error and repojacking targets namespace reuse and package installation automation.
How typo-squatting differs from repojacking in package ecosystems
Typo-squatting and repojacking both abuse trust in software distribution, but they do it in different ways. Typo-squatting depends on a developer mistyping a package name and pulling in a malicious lookalike. Repojacking depends on a trusted namespace being abandoned, renamed, or reused so an attacker can publish code under a name users already trust.
In practice, typo-squatting is about name confusion at install time, while repojacking is about namespace control and the persistence of trust after ownership changes. That means typo-squatting tends to exploit human error, whereas repojacking often exploits automation, dependency resolution, and assumptions that a familiar project name still points to the original maintainer.
For the reader, the key distinction is that typo-squatting attacks the moment of selection, but repojacking attacks the legitimacy of the source itself. A typo-squatted package may never have had any relationship to the original project. A repojacked package or repository, by contrast, can inherit trust from an earlier version of the project name, which makes detection harder and can let malicious code appear to be a routine update.
Why the two attack paths create different supply chain failure modes
Typo-squatting usually succeeds when developers install by memory, autocomplete, or copy-paste and do not verify the exact package identity. Repojacking usually succeeds when maintainers fail to protect abandoned names, repository redirects, or dependency references that still resolve to an old namespace. PyPI breach and Nx Package Attack illustrate how package ecosystems can be turned into delivery paths for malicious code and credential theft.
The practical consequence is that the control focus differs. Typo-squatting is reduced by better name review, package allowlisting, and dependency hygiene. Repojacking is reduced by namespace stewardship, repository transfer controls, ownership verification, and removal of stale references. Both threats abuse trust signals, but the signal being abused is not the same.
That difference matters when teams review build and dependency workflows. If the main weakness is developer error, the answer is tighter package selection controls. If the main weakness is namespace reuse or abandoned ownership, the answer is stronger repository governance and lifecycle management. Treating them as the same threat usually produces controls that are too generic to block either one well.
How practitioners should respond to each risk
Use different checks for each pattern. For typo-squatting, compare the package name, publisher, download source, and installation source before approving a dependency. For repojacking, confirm who owns the repository, whether the project was renamed or abandoned, and whether old package references still point to an attacker-controlled namespace. OpenSSF and SLSA are useful anchors for supply chain integrity and provenance thinking.
Decision rule: if the risk is a human might install the wrong package, focus on name verification and dependency policy. If the risk is a trusted project name can be reused or captured, focus on ownership controls, repository lifecycle review, and release provenance. In both cases, the operational goal is to make trust explicit instead of assuming the package name itself is proof of safety.
What to verify: Check whether your build system resolves packages from pinned sources, whether abandoned repositories are monitored for namespace reuse, and whether package provenance is being validated at install time. A name that looks familiar is not enough on its own.
Practitioner takeaway: Typo-squatting is a naming deception problem, while repojacking is a trust-transfer problem, so the right defense is to verify both the package identifier and the legitimacy of the namespace behind it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
SLSA, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| SLSA | Supply chain levels for software artifacts | Package provenance and integrity are central to both attack types. |
| Recommendation — Adopt provenance checks and artifact integrity controls before accepting dependencies. | ||
| CIS Controls v8 | CIS-16 — Application Software Security | Covers secure dependency handling and software supply chain controls. |
| CIS-5 — Account Management | Repojacking depends on stale ownership and namespace lifecycle weakness. | |
| Recommendation — Enforce software supply chain review for third-party dependencies and updates. Review abandoned repository ownership and remove stale access paths promptly. | ||
| NIST SP 800-53 Rev 5 | SA-12 — Supply Chain Protection | Directly addresses protecting software and package supply chains from tampering. |
| CM-10 — Software Usage Restrictions | Supports dependency allowlisting and blocking unapproved packages. | |
| Recommendation — Require supply chain protections for externally sourced packages and code. Restrict package sources to approved repositories and trusted publishers. | ||
Related resources from NHI Mgmt Group
- What is the difference between package scanning and runtime monitoring for npm supply chain attacks?
- What is the difference between protecting developer credentials and protecting package integrity in a supply chain attack?
- What is the difference between package compromise and secrets exposure in a supply chain attack?
- What is the difference between a benign educational package and a malicious package in a supply chain attack?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org