HomeSecurityTyposquatting is now a supply chain problem

Typosquatting is now a supply chain problem

Look-alike domains, generated by artificial intelligence, are now embedded in third-party scripts running on your web properties. Typosquatting is no longer a user problem. Attackers are now embedding look-alike domains inside legitimate third-party scripts, eliminating the need for URL mistypes or server compromises.

See also: DAEMON Tools Supply Chain Attack: Government organizations targeted

typosquatting
Typosquatting is now a supply chain problem

Artificial intelligence has revolutionized the economics of defense. Large Language Models (LLMs) can generate thousands of convincing domain variations in minutes, with full campaign deployment taking less than ten minutes. Malicious package uploads increased by 156% last year, making manual verification ineffective.

Your security stack lacks visibility into this issue. Firewalls, Web Application Firewalls (WAFs), Endpoint Detection and Response (EDR) , and Content Security Policies (CSP) cannot monitor what approved scripts do once they run in the browser.

The Trust Wallet attack is an example of this problem. $8.5 million was stolen in 48 hours via a modified Chrome extension. No alerts were triggered, not because of a failure, but because there was no monitoring.

On December 24, 2025, Trust Wallet users began losing money, not because they clicked on a phishing link or reused a weak password, but because of a self-replicating npm worm called Shai-Hulud. This worm harvested developer credentials, including GitHub tokens and Chrome Web Store API credentials, allowing attackers to push a modified version of the Trust Wallet Chrome extension through official channels. Chrome’s verification process approved it.

See also: SloppyLemming targets critical infrastructure in Pakistan and Bangladesh

Typosquatting is now a supply chain problem
Typosquatting is now a supply chain problem

The malicious extension ran entirely within users’ browsers, capturing seed phrases and transmitting them to the attacker’s infrastructure on a domain that was disguised as the Trust Wallet analysis point. Within 48 hours, 2,500 wallets were emptied, with a total loss of $8.5 million. No servers were compromised and no alerts were triggered.

What remains is this: a trusted component delivered via a browser was silently modified to intercept sensitive user data before the legitimate application could process it, remaining invisible to server logs, firewalls, WAFs, and EDR. This happened not because these controls were misconfigured, but because they were never designed to observe what was happening inside a browser session, even a compromised one.

This attack pattern can be replicated by replacing seed phrases with payment data and the Chrome extension with a marketing pixel or support widget. A typical e-commerce checkout page runs 40-60 third-party scripts, each of which represents a trusted connection, making similar attacks possible.

Typosquatting has evolved into three phases. The complexity of Phase 3 is not only technical, but also economic. LLMs can generate thousands of convincing domain variations quickly. Homography attacks use different character sets to create visually identical domains that evade detection.

See also: Shai-Hulud & Co.: The software supply chain as a weakness

Typosquatting is now a supply chain problem

Domain registration, SSL issuance, and full campaign deployment now take less than ten minutes. Data from Sonatype shows that malicious package uploads to open source repositories increased by 156% year-over-year, making manual verification structurally impossible.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS