All resourcesThreat brief1 min read

Copycat packages and the agent that installs them

Agents install dependencies in seconds. Attackers only need one look-alike name to be in the right place at the right time.

Sting Labs· 27 Sep 2026
Two almost identical parcels sit on a shelf; a bug peeks out of one while the robot reaches for it, and the Sting mascot points to the safe one.

Two parcels on the shelf

Package registries are huge and anyone can publish. A look-alike package borrows the name of a popular library with a swapped letter, an extra dash, or a plausible suffix, and waits for someone to type it.

People make that typo occasionally. Agents install dependencies far more often, and much faster.

When the name is made up

Language models sometimes confidently suggest a package that does not exist. If an attacker has registered that exact name, the install succeeds and pulls in their code instead of failing harmlessly.

In plain words

The agent asked for a parcel by name. Someone made sure a parcel with that name was waiting, and it was not the one you wanted.

Why speed makes it worse

Install scripts can run code the moment a package lands, before anyone reviews a single line. In a busy session an agent might add several dependencies in a row, each one accepted in a heartbeat.

What helps

Treat installs as actions worth checking: unknown or brand-new packages, names that sit suspiciously close to popular ones, and packages the task does not seem to need. Letting the routine installs through quickly is part of the job; pausing the strange ones is the rest.

Keep reading

All resources

See Sting guard your agents.

Book a 20-minute demo with a Sting expert. We'll walk through Observe and Protect on the kind of work your agents already do.

Book a demo