A cybersecurity analyst at a software development firm is investigating an incident where unauthorized code was introduced into a production build pipeline. The incident response log indicates two distinct actions taken by the threat actor: first, developers received bogus IT support tickets directing them to re-authenticate at an external single-sign-on domain (`login-company-auth.com`) that mimicked the company's internal portal; second, the attacker uploaded malicious software libraries to a public package repository using names with subtle typographical variations of legitimate internal dependencies (e.g., `core-utils-lib` vs. `core-utiis-lib`). Which of the following social engineering attack techniques were directly executed in this scenario? (Select TWO.)
- Pretexting by creating a fabricated IT support scenario to trick developers into disclosing credentials on a rogue authentication portalCevap
- Typosquatting by registering public package names that visually mimic legitimate internal library names to trick developers into pulling malicious dependenciesCevap
- CVishing by making automated interactive voice calls to developer smartphones to intercept multi-factor authentication codes
- DWatering hole attack by compromising a popular public tech news forum frequently visited by company engineers to deliver browser exploits