The repository names are identical to other repositories, indicating typo-squatting. These repositories also contain search keywords and emojis, signifying potential AI use. ReversingLabs warns developers that to avoid threat, it’s crucial to compare the repository in use to a previous, verified version of the software or source code.

One-two punch delivered in global operation disrupts cybercrime "assembly line"
International authorities and a raft of private technology companies say they have disrupted a cybercrime “assembly line” that allowed crooks to collect millions of login


