Copycat packages and the agent that installs them
Agents install dependencies in seconds. Attackers only need one look-alike name to be in the right place at the right time.
Sting Labs· 27 Sep 2026
Two parcels on the shelf
Package registries are huge and anyone can publish. A look-alike package borrows the name of a popular library with a swapped letter, an extra dash, or a plausible suffix, and waits for someone to type it.
People make that typo occasionally. Agents install dependencies far more often, and much faster.
When the name is made up
Language models sometimes confidently suggest a package that does not exist. If an attacker has registered that exact name, the install succeeds and pulls in their code instead of failing harmlessly.

In plain words
The agent asked for a parcel by name. Someone made sure a parcel with that name was waiting, and it was not the one you wanted.
Why speed makes it worse
Install scripts can run code the moment a package lands, before anyone reviews a single line. In a busy session an agent might add several dependencies in a row, each one accepted in a heartbeat.
What helps
Treat installs as actions worth checking: unknown or brand-new packages, names that sit suspiciously close to popular ones, and packages the task does not seem to need. Letting the routine installs through quickly is part of the job; pausing the strange ones is the rest.



