Feed
CriticalPublished 8 Sept 202671 packages · 73 versions

GitHub Advisory malware sweep - 2026-09-07/08 large corporate-namespace dep-confusion wave (Air Canada, Medisend, OPAP, Optimizely/Fastly, MATLAB/Azure DevOps, SimpliSafe, Tidal, PayPal, Twilio, Afterpay, Ecobee, Karapace, Glia, Jobber, Feishu, BMC, Coinbase-adjacent) + oast.online-beaconed probe cluster + 2026-09-08 fresh drops

Summary

Between 2026-09-07 and 2026-09-08 UTC GHSA flushed 100+ npm advisories in a single wave dominated by corporate-namespace dep-confusion probes (Air Canada, Medisend, Swisscom, OPAP, Optimizely/Fastly, MATLAB/Azure DevOps, SimpliSafe, Tidal, PayPal, Twilio, Afterpay, Ecobee, Karapace, Glia, Jobber, Feishu, BMC, and more). Two probes exposed shared IOCs (oast.online + 5.189.159.252). Plus 2026-09-08 fresh drops (krdpass-auth-react-native, PyPI telegram-helper).

dependency-confusiontyposquatcredential-theftdns-exfiltrationinfostealerci-cd-compromise
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis
Also known as
2026-09-08 GHSA corporate-namespace dep-confusion wave · oast.online / 5.189.159.252 preinstall.js beacon cluster · caliperx2-* + swisscom-oce-* dep-confusion probe operator
Ecosystems
npmPyPI
Packages tracked
71

What happened

Between roughly 2026-09-07 00:00 UTC and 2026-09-08 09:00 UTC, GitHub Advisory Database published 100+ new malware advisories in what is by volume the largest single-day dep-confusion probe wave of 2026 so far. Most cluster into three overlapping shapes below. Two probes exposed enough infrastructure detail to identify the operator pattern; the rest carry the standard GHSA full-compromise boilerplate and no explicit IOCs. The multi-2026-09-07-ghsa-malware-sweep module already covers the parallel E-prefix / tea.xyz / z3n autopublish backfill from the same window - this record covers the corporate-namespace dep-confusion wave that landed alongside it.

Cluster A - Confirmed shared-infrastructure dep-confusion probes

Two Sept 7 advisories included explicit preinstall-script details:

@caliperx2/components (GHSA-4jpr-935q-33r2): "The package name is a copy of a private, internal package name. The package executes a preinstall.js script during installation that gathers system information including hostname, username, directory paths, OS details, and Node.js version. It transmits collected data through three methods: DNS requests to oast.online subdomains, HTTPS/HTTP POST requests to oast.online, and HTTP POST to IP address 5.189.159.252. Uses a fixed token identifier: caliperx2-4d5f8e2a9b1c."

b2b-frontend-external-library (GHSA-hmhj-jhrj-285j): identical preinstall behaviour, identical infrastructure (oast.online + 5.189.159.252), different per-target token (swisscom-oce-3b9f1c7a2e - Swisscom Open Cloud Environment).

Same infrastructure + per-target token identifier = single-operator dep-confusion probe campaign. The oast.online egress is Project Discovery's Interactsh service (a legitimate OAST callback host commonly used by both bug-bounty researchers and offensive-security operators); 5.189.159.252 is a Contabo VPS - typical throw-away probe infrastructure.

Assume every other advisory in this wave that carries the shorter full-compromise GHSA boilerplate uses the same or an equivalent preinstall-beacon shape. GHSA metadata is thin on most of them because the automated flag/quarantine pipeline landed before human analysts wrote IOC-rich descriptions.

Cluster B - Scoped corporate-namespace impersonators

Air Canada scope - @aircanada/components, @aircanada/navigation-handler, @aircanada/core. Air Canada does not publish npm packages under a public @aircanada scope, so any resolution is a dep-confusion probe against internal AC engineering tooling.

Medisend scope - @medisend/core, @medisend/shared, @medisend/auth, @medisend/webview-bridge. Four-package fan-out mirroring a typical mobile-SDK internal split (core + shared + auth + webview-bridge) - highly targeted at Medisend's medical dispatch platform.

Cp-shared-14 scope - @cp-shared-14/frontend-ui@6.3.4. Interesting: pinned to a very specific version rather than 0.0.0, and OpenSSF Package Analysis flagged it (rather than the shorter full-compromise boilerplate) with "communicates with a domain associated with malicious activity" and "executes one or more commands associated with malicious behavior." The cp-shared-14 name shape suggests an internal shared-components scope at an opaque enterprise (channel-partner / commerce-platform naming pattern).

OPAP scope - @opap/player-kyc-widget. OPAP is the Greek state gaming/lottery operator; player-kyc-widget reads as their internal player-onboarding KYC frontend.

Jacksher scope - @jacksher/install-exec-poc - literal "install-exec-poc" suffix. Combined with @idkruan-10/dpd-depconf-probe (explicit dpd-depconf-probe), several of these Sept 7 uploads are labelled as PoC probes by their own authors.

Caliperx2 scope - @caliperx2/components (see Cluster A). caliperx2 maps to Caliper (SIS learning-analytics standard) enterprise scope.

Cluster C - Unscoped vendor / product name shadows

A sprawling long tail of bare unscoped names lining up with real vendor products:

| Package | Target vendor / product | |---|---| | openai-pr-reviewer | OpenAI + GitHub Actions PR-review bot | | github-app-sts-action | GitHub App STS-token action | | octopus-action | Octopus Deploy CI action | | matlab-azure-devops-extension | MathWorks MATLAB + Azure DevOps extension | | karapace-docs | Aiven Karapace (Kafka schema registry) docs | | optimizely-starter-kit-for-fastly-compute | Optimizely on Fastly Compute@Edge | | hyper-kube-config | Kubernetes config tooling | | simplisafe-gatsby | SimpliSafe alarm + Gatsby site | | tidal-embed-player | Tidal music embed player | | paypal-postman-lib | PayPal + Postman helper lib | | twilio-voice-js-reference-components | Twilio Voice JS | | afterpay-sdk-example-server | Afterpay BNPL SDK sample | | ecobee-api / ecobee2 / ecobee-home | Ecobee smart thermostat | | glia-functions-tools | Glia customer-service AI functions | | jobber-app-template-react | Jobber field-service | | feishu-docx-mcp | Feishu / Lark docs MCP | | bmc-i18n-extract-cli / bmc-translate-utils | BMC Software CLI helpers | | dbt-language-server | dbt data-build-tool LSP | | passkeys-react | WebAuthn / passkeys React SDK | | forge-extended | node-forge extended | | remove-bg-serverless-azure | remove.bg + Azure Functions | | dojo-rn-interview | Dojo payments React Native interview | | omni-channel-configurator-wireline-frontend | Telco omnichannel wireline frontend | | service-home / content-publisher-sdks / tool-registry-scripts | Generic internal-service naming | | starship-timeline / llm-traces-app / technical-challenge | Misc opportunistic | | boardwalk-js-tests / triage_bot_using_sdkv3 | Generic vendor sample names | | prism-registry | Stoplight Prism (OpenAPI mock) | | orbitron-tui / orbitron-cli | Orbitron branded CLI/TUI | | wolverinechat / op-ts-server-core | Generic name grab | | redis-type-intel / oscar-redis | Redis-adjacent naming | | kiki-baileys | Baileys WhatsApp library | | blueai-cli / prime-coding-agent / agent-free / agentrc-security-poc-policy | AI-agent naming pattern | | digitalexp-style-module-l9 | Corporate design-system scope | | global-intel / dynstrg-howto / knowledge-grader | Misc |

Each carries the standard GHSA full-compromise boilerplate; assume the same or an equivalent preinstall-beacon shape as Cluster A pending independent per-package analysis.

Cluster D - Ecosystem typosquats

  • log-update-ts - typosquat of the widely-used log-update package (sindresorhus)
  • chai-as-synced - typosquat of the very-widely-used chai-as-promised
  • aedes_clusters - dep-confusion vs Aedes MQTT clustering plugin naming
  • kelly-stake-sizing - Kelly-criterion betting/finance util
  • vishal_312pkg - test-drop opportunistic

Cluster E - Fresh 2026-09-08 drops

krdpass-auth-react-native (GHSA-3j7p-44mj-76hx, npm, all versions) - React Native auth wrapper name-grab, standard GHSA full-compromise boilerplate, no additional detail.

PyPI telegram-helper@0.1.1 and 0.1.2 (GHSA-vxg4-4jxm-7ff9) - genuinely different: "This malware package contains hidden code that starts a Telegram bot to exfiltrate sensitive session files and cookies. The malware executes remote commands on infected machines and steals browser data." This is a confirmed infostealer with C2 (the Telegram bot) rather than an install-time reconnaissance probe. On any lockfile hit, treat the host as an infostealer victim - browser cookies, session files, saved Telegram sessions are all in scope for immediate rotation.

Distinction from the parallel 2026-09-07 sweeps

Yesterday's multi-2026-09-07-ghsa-malware-sweep covered the parallel E-prefix alphabetical backfill (tea.xyz eka-* autopublish spam, tea.xyz eigenstate-* autopublish spam, effective_/efficient_<animal>_z3n research-pattern spam, and misc E-prefix opportunistic drops - registry-pollution rather than targeted attack). Yesterday's npm-2026-09-07-coinbase-base-cb-wallet-dep-confusion covered the parallel Coinbase / Base / SCW namespace probe (13 packages, one operator, one target). Both were catalogued as separate records with narrower scope.

This record covers the third parallel wave: the sprawling ~90-package multi-target corporate-namespace probe fan-out that landed alongside them, plus the 2026-09-08 fresh drops. All three waves appear operationally distinct - different naming conventions, different targeting, different volumes - but overlapped in time.

Registry state

All packages listed below are flagged as malware on npm / PyPI and quarantined. Private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs before quarantine will keep serving them - explicit deny-listing of every name below plus the @aircanada/, @medisend/, @cp-shared-*/, @opap/, @jacksher/, @caliperx2/ scopes is the durable mitigation.

Discovery credits

GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis (source for the @cp-shared-14/frontend-ui, cv-train, and agentrc-security-poc-policy advisories). Cluster A IOC details (oast.online, 5.189.159.252, per-target token) drawn verbatim from GHSA advisory bodies published by the OpenSSF Package Analysis pipeline.

Affected packages (71)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • Cluster A - Dep-confusion probes with confirmed shared IOCs (oast.online + 5.189.159.252, preinstall.js beacon): @caliperx2/components (token caliperx2-4d5f8e2a9b1c, GHSA-4jpr-935q-33r2) and b2b-frontend-external-library (token swisscom-oce-3b9f1c7a2e, GHSA-hmhj-jhrj-285j) both ship a preinstall.js that harvests hostname, username, cwd, OS, and Node version, then beacons via three redundant channels: DNS to <hex-payload>.oast.online, HTTPS POST to oast.online, HTTP POST to http://5.189.159.252/. Same infrastructure, different per-target token - this is a single-operator dep-confusion probe campaign fanning across multiple corporate namespaces. Any host that resolved one is confirmed compromised on install and the exfil channel is DNS-observable in enterprise DNS logs
  • Cluster B - Scoped corporate-namespace impersonators (dep-confusion probes, same wave, IOCs not yet published): @aircanada/components / @aircanada/navigation-handler / @aircanada/core (Air Canada), @medisend/core / @medisend/shared / @medisend/auth / @medisend/webview-bridge (medical dispatch platform), @cp-shared-14/frontend-ui@6.3.4 (opaque enterprise scope, OpenSSF-flagged), @opap/player-kyc-widget (OPAP Greek gaming corp KYC widget), @jacksher/install-exec-poc (explicit install-exec PoC), @idkruan-10/dpd-depconf-probe (explicit dpd-depconf-probe from OpenSSF-catalogued researcher scope). Each carries the full-compromise GHSA boilerplate ("any computer that has this package installed or running should be considered fully compromised") - assume the same preinstall-beacon shape as Cluster A until proven otherwise
  • Cluster C - Unscoped vendor / product name shadows (dep-confusion probes): 50+ packages whose names line up one-for-one with well-known vendors and enterprise products: openai-pr-reviewer (OpenAI + GitHub Actions PR review bot), github-app-sts-action (GitHub App STS token action), octopus-action (Octopus Deploy action), matlab-azure-devops-extension (MathWorks + Azure DevOps), karapace-docs (Aiven Karapace schema registry), optimizely-starter-kit-for-fastly-compute (Optimizely + Fastly Compute@Edge), hyper-kube-config (Kubernetes config tooling), simplisafe-gatsby (SimpliSafe alarm + Gatsby), tidal-embed-player (Tidal music embed), paypal-postman-lib (PayPal + Postman helper lib), twilio-voice-js-reference-components (Twilio Voice JS), afterpay-sdk-example-server (Afterpay BNPL SDK), ecobee-api / ecobee2 / ecobee-home (Ecobee smart thermostat), glia-functions-tools (Glia customer-service AI functions), jobber-app-template-react (Jobber field-service), feishu-docx-mcp (Feishu / Lark docs MCP), bmc-i18n-extract-cli / bmc-translate-utils (BMC Software CLI helpers), dbt-language-server (dbt data-build-tool LSP), passkeys-react (WebAuthn / passkeys React SDK), forge-extended (node-forge extended), remove-bg-serverless-azure (remove.bg + Azure Functions), dojo-rn-interview (Dojo payments React Native interview repo), omni-channel-configurator-wireline-frontend (telco omnichannel), agentrc-security-poc-policy (OpenSSF-analyzed PoC), agent-free, service-home, content-publisher-sdks, tool-registry-scripts, starship-timeline, llm-traces-app, technical-challenge, boardwalk-js-tests, triage_bot_using_sdkv3, knowledge-grader, prism-registry (Stoplight Prism), global-intel, dynstrg-howto, prime-coding-agent, orbitron-tui / orbitron-cli, wolverinechat, op-ts-server-core, redis-type-intel, oscar-redis, kiki-baileys (Baileys WhatsApp), blueai-cli, digitalexp-style-module-l9. Any bare-name pin in a real lockfile is high-confidence compromise on install
  • Cluster D - Ecosystem typosquats and misc: log-update-ts (typosquat of log-update), chai-as-synced (typosquat of chai-as-promised), aedes_clusters (typosquat / dep-confusion vs Aedes MQTT clustering plugins), kelly-stake-sizing (finance/betting util), vishal_312pkg (test-drop opportunistic), plus a handful of miscellaneous plain-name drops. Same GHSA full-compromise boilerplate; treat identically
  • Cluster E - Fresh 2026-09-08 drops: krdpass-auth-react-native (npm, all versions, GHSA-3j7p-44mj-76hx - React Native auth wrapper name-grab) and PyPI telegram-helper@0.1.1 / 0.1.2 (GHSA-vxg4-4jxm-7ff9 - "starts a Telegram bot to exfiltrate sensitive session files and cookies", executes remote commands, steals browser data). The PyPI drop is the more actionable of the two - it is a confirmed infostealer, not just install-time reconnaissance

What to do

  1. 1Grep every package-lock.json, yarn.lock, pnpm-lock.yaml, package.json, requirements.txt, poetry.lock, and Pipfile.lock in your org for the names below. Uninstall on hit and rebuild the lockfile against a clean cache
  2. 2For Cluster A hits (confirmed IOCs): audit DNS logs for queries to *.oast.online between 2026-09-07 and now; audit HTTP egress logs for connections to 5.189.159.252. Any host with a matching DNS or egress record is confirmed compromised - rotate every credential the host had access to (npm tokens, cloud IAM, SSH keys, git credentials, SSO), reimage, forensicate. Block oast.online and 5.189.159.252 at your egress proxy
  3. 3For Cluster B/C/D lockfile hits: treat the resolving host as fully compromised per GHSA boilerplate. Rotate npm tokens, cloud IAM, SSH keys, git credentials, SSO; wipe node_modules, delete the lockfile, rebuild against a clean cache. The same oast.online / 5.189.159.252 beacon shape should be assumed until each specific package is independently analyzed
  4. 4For Coinbase, Air Canada, Medisend, OPAP, Swisscom, Optimizely, Fastly, MathWorks, SimpliSafe, Tidal, PayPal, Twilio, Afterpay, Ecobee, Aiven (Karapace), Glia, Jobber, BMC, Feishu/Lark, dbt Labs, Octopus Deploy, Jacksher, Caliperx, and any org whose internal namespace appears above: audit internal npm mirror resolution logs for any of the exact names below. Any resolution attempt against a public-registry version of an internal name is dep-confusion exposure regardless of whether the malware executed - the naming pattern proves an attacker enumerated your internal package inventory
  5. 5Explicit scoped-registry pinning in .npmrc: for @aircanada/, @medisend/, @cp-shared-*/, @opap/, @jacksher/, @caliperx2/, and every other internal npm scope, add explicit registry= lines to .npmrc and enforce them in CI. Never rely on bare unscoped names to resolve to an internal package - dep-confusion works by racing against the internal name over public npm
  6. 6For every npm install in CI, prefer --ignore-scripts to block postinstall / preinstall payloads. This is the single highest-value mitigation against the Cluster A/B/C probe shape - preinstall.js never runs if scripts are disabled
  7. 7For the 2026-09-08 PyPI telegram-helper drop: grep every requirements.txt, poetry.lock, Pipfile.lock, and pyproject.toml for telegram-helper. On hit, immediately triage the host as an infostealer victim: browser cookies, session files, and Telegram credentials are the primary theft targets. Wipe the host, rotate every session cookie and browser-stored password, and rotate Telegram sessions from a different device
  8. 8Add all Cluster A/B/C/D names to internal private-registry (Verdaccio / Artifactory / Nexus) deny-lists for at least 30 days to prevent re-uploads under the same names by rotating operators

References

multi-2026-09-08-ghsa-malware-sweep