5 ms·
So they caught the guy using a cliched I-vs-l typosquatting scheme and lazily writing the malicious code in Python; we can presume they haven't caught the guy w
by maxander 7y ago
So they caught the guy using a cliched I-vs-l typosquatting scheme and lazily writing the malicious code in Python; we can presume they haven't caught the guy who took the trouble to put their malicious code in a pre-compiled C extension.
Reminds me of the fraudulent scientific papers that get caught using really dumb fakes (e.g., microscopy pictures that are copies of one another re-zoomed and rotated); we catch the dumb ones, but presumably not all malicious actors are dumb, so there must be a lot more fraudulent work out there.
For that matter, isn't there a reasonable systematic way to catch out typosquatters simply based on text analysis? Any library name that's a short edit distance from a popular library should have been carefully reviewed from the start; there's no excuse for "jeilyfish" to have lasted more than a couple of days.
- commandersaki 7y ago> For that matter, isn't there a reasonable systematic way to catch out typosquatters simply based on text analysis? You could probably write one using Python & jellyfish.
- CGamesPlay 7y agoI'm extremely disappointed to see that you didn't suggest using jeIlyfish instead.
- rmtech 7y agonicely done
- maxander 7y agoFrom jellyfish’s pypi page: “ a library for doing approximate and phonetic matching of strings.” Huh! Hadn’t realized. That adds an ironic spin to the whole thing.