AI GlossaryㅇSafety and controversy
Typosquatting
An attack that registers a name no one has claimed yet, then hijacks whoever or whatever trusts and connects to or installs from that name.
In plain words
Typosquatting is a trick where an attacker secretly grabs a name that nobody has registered yet, then intercepts whoever comes looking for it. It's like registering a P.O. box number at the post office that no one has claimed, then intercepting whatever mail arrives at that number. The attack originally targeted people, buying up similarly spelled web addresses in hopes someone would mistype a URL — but these days, the target is increasingly not a person but a program.
The issue causing trouble right now is AI coding agents. These agents are designed to automatically find and install whatever code packages are named in a document — but if that document happens to reference a package name that doesn't actually exist, things go wrong. If someone registers that unclaimed name first and plants malicious code there, an agent that blindly trusts the document will pull down and install that malicious code automatically. A human might pause at an unfamiliar name, but an agent executes without hesitation — which is exactly why this attack has become especially dangerous lately.
How it shows up in the news
Articles explain that this works on the same principle as the already-known "dependency confusion" attack in software supply chains — the difference this time is that the one executing the action is an AI agent, not a human. The key point, often misunderstood, is that this attack doesn't exploit any new vulnerability — simply claiming an unregistered name is enough to pull it off.
Try it yourself
If your company has AI coding agents read internal documents or files like llms.txt to do their work, check every package name and domain mentioned in those documents against what your company has actually registered and owns. If a name listed doesn't actually exist, one option is to go ahead and officially register it yourself first.
See also
Stories using this term
- AI coding agents auto-install unregistered links from llms.txt, breach corporate networksBusiness · 2026.08.28
- Copilot confessed its own bypass password when repeatedly questionedBusiness · 2026.08.19
- LiteLLM Supply Chain Attack Exposes Credentials of 2,500 OrganizationsBusiness · 2026.08.13
- Tencent's Zhuque Lab Open-Sources AI Agent/MCP Security ScannerAI · 2026.08.21
- Existing Token Benchmarks Cannot Rank Coding-Agent LanguagesAI · 2026.08.11
- DeepSeek-V4-Flash-0731 reported to stall during long-context tasksAI · 2026.08.10
