How to Detect and Prevent Typosquatting Attacks

Intermediate 20 minutes Security Engineers Security & Policy

Understand Chainsaw's BK-tree typosquat detection, review flagged packages, and create policies that block suspected typosquats.

Overview

Typosquatting is a supply chain attack where malicious actors publish packages with names similar to popular ones (e.g., lodsah instead of lodash). Chainsaw detects these attacks in real-time using a BK-tree algorithm that compares every incoming package name against a database of popular packages per ecosystem.

Detection runs inline in under 5ms and catches:

  • Edit-distance attacks — transposed, added, or removed characters
  • Homoglyph attacks — visually similar characters (e.g., rn vs m)
  • Combosquat attacks — appending common suffixes (e.g., lodash-utils)
  • Word-reorder attacks — rearranging the same tokens (e.g., http-auth-node vs node-http-auth)

Prerequisites

  • Admin or Manager role in Chainsaw
  • Packages flowing through the proxy (typosquat detection is automatic)

Step 1: Understand How Detection Works

When a package is requested through Chainsaw, the supply chain orchestrator runs typosquat detection as a synchronous check:

  1. The package name is compared against popular packages in the same ecosystem
  2. The BK-tree returns matches within a configurable edit distance
  3. Results include a confidence level (high, medium, low) and the similar package it matched against
Typosquat detection flow diagram
Typosquat detection runs inline on every package request
Thirteen ecosystems are enrolled in typosquat detection: npm, PyPI, Cargo, Composer, RubyGems, NuGet, Docker, Hugging Face, Maven, Gradle, Swift, Go, and CocoaPods. APT / Yum / DNF are classified low-risk and skipped — package names there are coordinated by distro maintainers. Go and CocoaPods were added in the most recent release and use curated seed lists bundled with Chainsaw, since neither ecosystem publishes a stable public top-N endpoint.

Step 2: Review Flagged Packages

Navigate to the Bill of Materials page. Packages flagged as suspected typosquats show a warning indicator in the Typosquat Status column.

StatusMeaning
CleanNo similarity to popular packages detected
SuspectedPackage name is suspiciously similar to a popular package
Confirmed SafeManually reviewed and marked as safe
BOM page with typosquat flags
Suspected typosquats are flagged in the Bill of Materials view

Click on a flagged package to see details:

  • Which popular package it’s similar to
  • The confidence level of the match
  • The edit distance and detection method
Typosquat detection details
Detailed typosquat analysis showing the similar package and confidence

Step 3: Create a Policy to Block Typosquats

Navigate to Policies and click Create Policy.

Configure the Policy

  1. Name: Block Suspected Typosquats
  2. Action: Block
  3. Condition: Typosquat Detection → suspected
Creating a typosquat blocking policy
Create a policy that blocks packages flagged as suspected typosquats

Choose Your Enforcement Level

You have several options:

ApproachPolicy ActionWhen to Use
Block all suspectedBlockHigh-security environments
Quarantine for reviewQuarantineTeams that need flexibility
Block high-confidence onlyBlock with confidence filterBalanced approach
Start with Quarantine to understand your false positive rate before switching to Block. Some legitimate packages may have names similar to popular ones.

Step 4: Monitor the Trust Score Impact

Typosquat detection affects the composite Trust Score for each package:

Detection ResultTrust Score Impact
Clean+10 points
Suspected (high confidence)-30 points
Suspected (medium confidence)-20 points

Navigate to the BOM page and sort by Trust Score to identify the highest-risk packages.

Trust scores showing typosquat impact
Suspected typosquats significantly reduce a package's trust score

Step 5: Handle False Positives

If a legitimate package is flagged as a typosquat:

  1. Review the package details in the BOM
  2. Create an exception for that specific package
  3. Navigate to Policies and create an Allow policy with higher precedence, scoped to that package
Creating an exception for a false positive
Create an exception for legitimate packages that trigger typosquat detection

Step 6: Use Billy to Investigate

Ask Billy to help identify typosquat patterns in your organization:

"Show me all packages flagged as suspected typosquats in the last 30 days"
"Which clients are installing packages with low trust scores?"
Billy answering a typosquat query
Use Billy to investigate typosquat patterns across your organization

Real-World Example

A developer accidentally types npm install axois instead of npm install axios. Without Chainsaw:

  1. npm fetches the typosquatted package from the public registry
  2. The malicious package executes post-install scripts
  3. Credentials are exfiltrated

With Chainsaw:

  1. The request hits the proxy
  2. Typosquat detection flags axois as similar to axios (edit distance: 1, high confidence)
  3. The blocking policy rejects the install
  4. The developer sees an error explaining the suspected typosquat

Next Steps