Join our Newsletter — 33% off our NHI Course
Home› Glossary› Identity Beyond IAM› Combo Squatting
Identity Beyond IAM

Combo Squatting

← Back to Glossary
By NHI Mgmt Group Updated September 24, 2026 Domain: Identity Beyond IAM

Combo squatting is a typosquatting variant where an attacker adds a plausible word to a legitimate package or project name to look authentic. In software supply chains, the goal is to blend into normal developer workflows and reduce suspicion long enough for malicious code to be installed and executed.

What Combo Squatting Looks Like in Package Ecosystems

Combo squatting is a supply chain impersonation pattern, not just a typo. The attacker chooses a legitimate-looking package name by appending a plausible word, such as a common framework, utility, or platform term, so the result feels like a normal extension of an existing project.

This works because developers often rely on naming cues during search, review, and dependency selection. A name that resembles an established package can be mistaken for an official companion, fork, or integration, especially when it appears in a large ecosystem with many similarly named artifacts.

Why Combo Squatting Bypasses Casual Review

The tactic succeeds by exploiting expectations about how packages are named and discovered. People tend to trust names that sound semantically related to a known project, even when the relationship is invented. That makes combo squatting more subtle than simple character swaps or single-letter typos.

It is especially effective when the malicious package mimics the naming style of the ecosystem itself. If the added word reflects a common feature, language, vendor, or deployment pattern, the package can look like a routine companion library rather than an attacker-controlled artifact.

That naming strategy is also useful for blending into automated workflows. Build systems, dependency update tools, and package search interfaces can surface the artifact before a human notices that the name is only plausible, not authentic.

How Combo Squatting Enables Supply Chain Compromise

The security issue is not the name alone, it is the trust it can create long enough for the package to be installed. Once a developer or pipeline pulls the artifact, malicious code can run in build, test, or runtime contexts depending on how the package is consumed.

That can turn a naming trick into broader software supply chain compromise, including credential theft, backdoor installation, or tampering with downstream builds. The impact often extends beyond the initial developer workstation because one poisoned dependency can be reused across projects and environments.

Combo squatting also widens the attacker’s opportunity window. A convincing package name can reduce suspicion during review, increase downloads, and make defensive triage slower because the package does not obviously look malformed.

Signals That Make Combo Squatting Harder to Detect

Combo-squatted packages often look legitimate at a glance because they imitate real naming conventions instead of breaking them. The most common blind spot is semantic plausibility: the name seems to fit the ecosystem even though it has no verified relationship to the original project.

Review becomes harder when the package metadata, description, or version history is thin, inconsistent, or newly created. That mismatch between a polished name and weak supporting context is often the clue that the package is trying to borrow trust from a known project.

Defenders should also watch for dependency discovery patterns that reward familiarity over provenance. When package selection depends on search ranking, autocomplete, or rapid installation behavior, attackers can exploit that convenience layer without needing to defeat stronger technical controls first.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while SLSA, OWASP SAMM, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
SLSASupply-chain Levels for Software ArtifactsCombo squatting targets software supply-chain integrity and artifact trust.
Recommendation — Use SLSA-aligned provenance checks to verify where packages came from before they enter builds.
OWASP SAMMSoftware Assurance Maturity ModelCombo squatting is defeated by mature dependency governance and secure build practices.
Recommendation — Build dependency vetting and third-party intake reviews into your secure software delivery process.
NIST CSF 2.0PR.DS-08 — Integrity mechanisms are implemented to verify software, data, and servicesCombo squatting undermines trust in package integrity and software origin.
ID.RA-01 — Asset vulnerabilities are identified and documentedPackage-name impersonation is a supply-chain weakness that should be identified in risk analysis.
Recommendation — Apply integrity verification to software artifacts before allowing them into production workflows. Document package discovery and dependency-selection weaknesses in your risk analysis.
CIS Controls v8CIS-16 — Application Software SecurityCombo squatting is an application supply-chain risk that belongs in secure software practices.
Recommendation — Treat third-party package selection as part of application software security review.
MITRE ATT&CKT1195 — Supply Chain CompromiseCombo squatting is a naming tactic used to support software supply-chain compromise.
Recommendation — Map suspicious package activity to supply-chain compromise techniques during threat hunting.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org