GitHub Advisory malware sweep - 2026-09-07/08 large corporate-namespace dep-confusion wave (Air Canada, Medisend, OPAP, Optimizely/Fastly, MATLAB/Azure DevOps, SimpliSafe, Tidal, PayPal, Twilio, Afterpay, Ecobee, Karapace, Glia, Jobber, Feishu, BMC, Coinbase-adjacent) + oast.online-beaconed probe cluster + 2026-09-08 fresh drops
Between 2026-09-07 and 2026-09-08 UTC GHSA flushed 100+ npm advisories in a single wave dominated by corporate-namespace dep-confusion probes (Air Canada, Medisend, Swisscom, OPAP, Optimizely/Fastly, MATLAB/Azure DevOps, SimpliSafe, Tidal, PayPal, Twilio, Afterpay, Ecobee, Karapace, Glia, Jobber, Feishu, BMC, and more). Two probes exposed shared IOCs (oast.online + 5.189.159.252). Plus 2026-09-08 fresh drops (krdpass-auth-react-native, PyPI telegram-helper).
- Detected by
- GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis
- Also known as
- 2026-09-08 GHSA corporate-namespace dep-confusion wave · oast.online / 5.189.159.252 preinstall.js beacon cluster · caliperx2-* + swisscom-oce-* dep-confusion probe operator
- Ecosystems
- npmPyPI
- Packages tracked
- 71
What happened
Between roughly 2026-09-07 00:00 UTC and 2026-09-08 09:00 UTC, GitHub Advisory Database published 100+ new malware advisories in what is by volume the largest single-day dep-confusion probe wave of 2026 so far. Most cluster into three overlapping shapes below. Two probes exposed enough infrastructure detail to identify the operator pattern; the rest carry the standard GHSA full-compromise boilerplate and no explicit IOCs. The multi-2026-09-07-ghsa-malware-sweep module already covers the parallel E-prefix / tea.xyz / z3n autopublish backfill from the same window - this record covers the corporate-namespace dep-confusion wave that landed alongside it.
Cluster A - Confirmed shared-infrastructure dep-confusion probes
Two Sept 7 advisories included explicit preinstall-script details:
@caliperx2/components (GHSA-4jpr-935q-33r2): "The package name is a copy of a private, internal package name. The package executes a preinstall.js script during installation that gathers system information including hostname, username, directory paths, OS details, and Node.js version. It transmits collected data through three methods: DNS requests to oast.online subdomains, HTTPS/HTTP POST requests to oast.online, and HTTP POST to IP address 5.189.159.252. Uses a fixed token identifier: caliperx2-4d5f8e2a9b1c."
b2b-frontend-external-library (GHSA-hmhj-jhrj-285j): identical preinstall behaviour, identical infrastructure (oast.online + 5.189.159.252), different per-target token (swisscom-oce-3b9f1c7a2e - Swisscom Open Cloud Environment).
Same infrastructure + per-target token identifier = single-operator dep-confusion probe campaign. The oast.online egress is Project Discovery's Interactsh service (a legitimate OAST callback host commonly used by both bug-bounty researchers and offensive-security operators); 5.189.159.252 is a Contabo VPS - typical throw-away probe infrastructure.
Assume every other advisory in this wave that carries the shorter full-compromise GHSA boilerplate uses the same or an equivalent preinstall-beacon shape. GHSA metadata is thin on most of them because the automated flag/quarantine pipeline landed before human analysts wrote IOC-rich descriptions.
Cluster B - Scoped corporate-namespace impersonators
Air Canada scope - @aircanada/components, @aircanada/navigation-handler, @aircanada/core. Air Canada does not publish npm packages under a public @aircanada scope, so any resolution is a dep-confusion probe against internal AC engineering tooling.
Medisend scope - @medisend/core, @medisend/shared, @medisend/auth, @medisend/webview-bridge. Four-package fan-out mirroring a typical mobile-SDK internal split (core + shared + auth + webview-bridge) - highly targeted at Medisend's medical dispatch platform.
Cp-shared-14 scope - @cp-shared-14/frontend-ui@6.3.4. Interesting: pinned to a very specific version rather than 0.0.0, and OpenSSF Package Analysis flagged it (rather than the shorter full-compromise boilerplate) with "communicates with a domain associated with malicious activity" and "executes one or more commands associated with malicious behavior." The cp-shared-14 name shape suggests an internal shared-components scope at an opaque enterprise (channel-partner / commerce-platform naming pattern).
OPAP scope - @opap/player-kyc-widget. OPAP is the Greek state gaming/lottery operator; player-kyc-widget reads as their internal player-onboarding KYC frontend.
Jacksher scope - @jacksher/install-exec-poc - literal "install-exec-poc" suffix. Combined with @idkruan-10/dpd-depconf-probe (explicit dpd-depconf-probe), several of these Sept 7 uploads are labelled as PoC probes by their own authors.
Caliperx2 scope - @caliperx2/components (see Cluster A). caliperx2 maps to Caliper (SIS learning-analytics standard) enterprise scope.
Cluster C - Unscoped vendor / product name shadows
A sprawling long tail of bare unscoped names lining up with real vendor products:
| Package | Target vendor / product | |---|---| | openai-pr-reviewer | OpenAI + GitHub Actions PR-review bot | | github-app-sts-action | GitHub App STS-token action | | octopus-action | Octopus Deploy CI action | | matlab-azure-devops-extension | MathWorks MATLAB + Azure DevOps extension | | karapace-docs | Aiven Karapace (Kafka schema registry) docs | | optimizely-starter-kit-for-fastly-compute | Optimizely on Fastly Compute@Edge | | hyper-kube-config | Kubernetes config tooling | | simplisafe-gatsby | SimpliSafe alarm + Gatsby site | | tidal-embed-player | Tidal music embed player | | paypal-postman-lib | PayPal + Postman helper lib | | twilio-voice-js-reference-components | Twilio Voice JS | | afterpay-sdk-example-server | Afterpay BNPL SDK sample | | ecobee-api / ecobee2 / ecobee-home | Ecobee smart thermostat | | glia-functions-tools | Glia customer-service AI functions | | jobber-app-template-react | Jobber field-service | | feishu-docx-mcp | Feishu / Lark docs MCP | | bmc-i18n-extract-cli / bmc-translate-utils | BMC Software CLI helpers | | dbt-language-server | dbt data-build-tool LSP | | passkeys-react | WebAuthn / passkeys React SDK | | forge-extended | node-forge extended | | remove-bg-serverless-azure | remove.bg + Azure Functions | | dojo-rn-interview | Dojo payments React Native interview | | omni-channel-configurator-wireline-frontend | Telco omnichannel wireline frontend | | service-home / content-publisher-sdks / tool-registry-scripts | Generic internal-service naming | | starship-timeline / llm-traces-app / technical-challenge | Misc opportunistic | | boardwalk-js-tests / triage_bot_using_sdkv3 | Generic vendor sample names | | prism-registry | Stoplight Prism (OpenAPI mock) | | orbitron-tui / orbitron-cli | Orbitron branded CLI/TUI | | wolverinechat / op-ts-server-core | Generic name grab | | redis-type-intel / oscar-redis | Redis-adjacent naming | | kiki-baileys | Baileys WhatsApp library | | blueai-cli / prime-coding-agent / agent-free / agentrc-security-poc-policy | AI-agent naming pattern | | digitalexp-style-module-l9 | Corporate design-system scope | | global-intel / dynstrg-howto / knowledge-grader | Misc |
Each carries the standard GHSA full-compromise boilerplate; assume the same or an equivalent preinstall-beacon shape as Cluster A pending independent per-package analysis.
Cluster D - Ecosystem typosquats
log-update-ts- typosquat of the widely-usedlog-updatepackage (sindresorhus)chai-as-synced- typosquat of the very-widely-usedchai-as-promisedaedes_clusters- dep-confusion vs Aedes MQTT clustering plugin namingkelly-stake-sizing- Kelly-criterion betting/finance utilvishal_312pkg- test-drop opportunistic
Cluster E - Fresh 2026-09-08 drops
krdpass-auth-react-native (GHSA-3j7p-44mj-76hx, npm, all versions) - React Native auth wrapper name-grab, standard GHSA full-compromise boilerplate, no additional detail.
PyPI telegram-helper@0.1.1 and 0.1.2 (GHSA-vxg4-4jxm-7ff9) - genuinely different: "This malware package contains hidden code that starts a Telegram bot to exfiltrate sensitive session files and cookies. The malware executes remote commands on infected machines and steals browser data." This is a confirmed infostealer with C2 (the Telegram bot) rather than an install-time reconnaissance probe. On any lockfile hit, treat the host as an infostealer victim - browser cookies, session files, saved Telegram sessions are all in scope for immediate rotation.
Distinction from the parallel 2026-09-07 sweeps
Yesterday's multi-2026-09-07-ghsa-malware-sweep covered the parallel E-prefix alphabetical backfill (tea.xyz eka-* autopublish spam, tea.xyz eigenstate-* autopublish spam, effective_/efficient_<animal>_z3n research-pattern spam, and misc E-prefix opportunistic drops - registry-pollution rather than targeted attack). Yesterday's npm-2026-09-07-coinbase-base-cb-wallet-dep-confusion covered the parallel Coinbase / Base / SCW namespace probe (13 packages, one operator, one target). Both were catalogued as separate records with narrower scope.
This record covers the third parallel wave: the sprawling ~90-package multi-target corporate-namespace probe fan-out that landed alongside them, plus the 2026-09-08 fresh drops. All three waves appear operationally distinct - different naming conventions, different targeting, different volumes - but overlapped in time.
Registry state
All packages listed below are flagged as malware on npm / PyPI and quarantined. Private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs before quarantine will keep serving them - explicit deny-listing of every name below plus the @aircanada/, @medisend/, @cp-shared-*/, @opap/, @jacksher/, @caliperx2/ scopes is the durable mitigation.
Discovery credits
GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis (source for the @cp-shared-14/frontend-ui, cv-train, and agentrc-security-poc-policy advisories). Cluster A IOC details (oast.online, 5.189.159.252, per-target token) drawn verbatim from GHSA advisory bodies published by the OpenSSF Package Analysis pipeline.
Affected packages (71)
- npm@aircanada/components0.0.0
- npm@aircanada/core0.0.0
- npm@aircanada/navigation-handler0.0.0
- npm@caliperx2/components0.0.0
- npm@cp-shared-14/frontend-ui6.3.4
- npm@idkruan-10/dpd-depconf-probe0.0.0
- npm@jacksher/install-exec-poc0.0.0
- npm@medisend/auth0.0.0
- npm@medisend/core0.0.0
- npm@medisend/shared0.0.0
- npm@medisend/webview-bridge0.0.0
- npm@opap/player-kyc-widget0.0.0
- npmaedes_clusters0.0.0
- npmafterpay-sdk-example-server0.0.0
- npmagent-free0.0.0
- npmagentrc-security-poc-policy1.0.0
- npmb2b-frontend-external-library0.0.0
- npmblueai-cli0.0.0
- npmbmc-i18n-extract-cli0.0.0
- npmbmc-translate-utils0.0.0
- npmboardwalk-js-tests0.0.0
- npmchai-as-synced0.0.0
- npmcontent-publisher-sdks0.0.0
- PyPIcv-train0.0.599.0.0
- npmdbt-language-server0.0.0
- npmdigitalexp-style-module-l90.0.0
- npmdojo-rn-interview0.0.0
- npmdynstrg-howto0.0.0
- npmecobee-api0.0.0
- npmecobee-home0.0.0
- npmecobee20.0.0
- npmfeishu-docx-mcp0.0.0
- npmforge-extended0.0.0
- npmgithub-app-sts-action0.0.0
- npmglia-functions-tools0.0.0
- npmglobal-intel0.0.0
- npmhyper-kube-config0.0.0
- npmjobber-app-template-react0.0.0
- npmkarapace-docs0.0.0
- npmkelly-stake-sizing0.0.0
- npmkiki-baileys0.0.0
- npmknowledge-grader0.0.0
- npmkrdpass-auth-react-native0.0.0
- npmllm-traces-app0.0.0
- npmlog-update-ts0.0.0
- npmmatlab-azure-devops-extension0.0.0
- npmoctopus-action0.0.0
- npmomni-channel-configurator-wireline-frontend0.0.0
- npmop-ts-server-core0.0.0
- npmopenai-pr-reviewer0.0.0
- npmoptimizely-starter-kit-for-fastly-compute0.0.0
- npmorbitron-cli0.0.0
- npmorbitron-tui0.0.0
- npmoscar-redis0.0.0
- npmpasskeys-react0.0.0
- npmpaypal-postman-lib0.0.0
- npmprime-coding-agent0.0.0
- npmprism-registry0.0.0
- npmredis-type-intel0.0.0
- npmremove-bg-serverless-azure0.0.0
- npmservice-home0.0.0
- npmsimplisafe-gatsby0.0.0
- npmstarship-timeline0.0.0
- npmtechnical-challenge0.0.0
- PyPItelegram-helper0.1.10.1.2
- npmtidal-embed-player0.0.0
- npmtool-registry-scripts0.0.0
- npmtriage_bot_using_sdkv30.0.0
- npmtwilio-voice-js-reference-components0.0.0
- npmvishal_312pkg0.0.0
- npmwolverinechat0.0.0
These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.
Impact
- Cluster A - Dep-confusion probes with confirmed shared IOCs (
oast.online+5.189.159.252, preinstall.js beacon):@caliperx2/components(tokencaliperx2-4d5f8e2a9b1c, GHSA-4jpr-935q-33r2) andb2b-frontend-external-library(tokenswisscom-oce-3b9f1c7a2e, GHSA-hmhj-jhrj-285j) both ship apreinstall.jsthat harvests hostname, username, cwd, OS, and Node version, then beacons via three redundant channels: DNS to<hex-payload>.oast.online, HTTPS POST tooast.online, HTTP POST tohttp://5.189.159.252/. Same infrastructure, different per-target token - this is a single-operator dep-confusion probe campaign fanning across multiple corporate namespaces. Any host that resolved one is confirmed compromised on install and the exfil channel is DNS-observable in enterprise DNS logs - Cluster B - Scoped corporate-namespace impersonators (dep-confusion probes, same wave, IOCs not yet published):
@aircanada/components/@aircanada/navigation-handler/@aircanada/core(Air Canada),@medisend/core/@medisend/shared/@medisend/auth/@medisend/webview-bridge(medical dispatch platform),@cp-shared-14/frontend-ui@6.3.4(opaque enterprise scope, OpenSSF-flagged),@opap/player-kyc-widget(OPAP Greek gaming corp KYC widget),@jacksher/install-exec-poc(explicit install-exec PoC),@idkruan-10/dpd-depconf-probe(explicit dpd-depconf-probe from OpenSSF-catalogued researcher scope). Each carries the full-compromise GHSA boilerplate ("any computer that has this package installed or running should be considered fully compromised") - assume the same preinstall-beacon shape as Cluster A until proven otherwise - Cluster C - Unscoped vendor / product name shadows (dep-confusion probes): 50+ packages whose names line up one-for-one with well-known vendors and enterprise products:
openai-pr-reviewer(OpenAI + GitHub Actions PR review bot),github-app-sts-action(GitHub App STS token action),octopus-action(Octopus Deploy action),matlab-azure-devops-extension(MathWorks + Azure DevOps),karapace-docs(Aiven Karapace schema registry),optimizely-starter-kit-for-fastly-compute(Optimizely + Fastly Compute@Edge),hyper-kube-config(Kubernetes config tooling),simplisafe-gatsby(SimpliSafe alarm + Gatsby),tidal-embed-player(Tidal music embed),paypal-postman-lib(PayPal + Postman helper lib),twilio-voice-js-reference-components(Twilio Voice JS),afterpay-sdk-example-server(Afterpay BNPL SDK),ecobee-api/ecobee2/ecobee-home(Ecobee smart thermostat),glia-functions-tools(Glia customer-service AI functions),jobber-app-template-react(Jobber field-service),feishu-docx-mcp(Feishu / Lark docs MCP),bmc-i18n-extract-cli/bmc-translate-utils(BMC Software CLI helpers),dbt-language-server(dbt data-build-tool LSP),passkeys-react(WebAuthn / passkeys React SDK),forge-extended(node-forge extended),remove-bg-serverless-azure(remove.bg + Azure Functions),dojo-rn-interview(Dojo payments React Native interview repo),omni-channel-configurator-wireline-frontend(telco omnichannel),agentrc-security-poc-policy(OpenSSF-analyzed PoC),agent-free,service-home,content-publisher-sdks,tool-registry-scripts,starship-timeline,llm-traces-app,technical-challenge,boardwalk-js-tests,triage_bot_using_sdkv3,knowledge-grader,prism-registry(Stoplight Prism),global-intel,dynstrg-howto,prime-coding-agent,orbitron-tui/orbitron-cli,wolverinechat,op-ts-server-core,redis-type-intel,oscar-redis,kiki-baileys(Baileys WhatsApp),blueai-cli,digitalexp-style-module-l9. Any bare-name pin in a real lockfile is high-confidence compromise on install - Cluster D - Ecosystem typosquats and misc:
log-update-ts(typosquat oflog-update),chai-as-synced(typosquat ofchai-as-promised),aedes_clusters(typosquat / dep-confusion vs Aedes MQTT clustering plugins),kelly-stake-sizing(finance/betting util),vishal_312pkg(test-drop opportunistic), plus a handful of miscellaneous plain-name drops. Same GHSA full-compromise boilerplate; treat identically - Cluster E - Fresh 2026-09-08 drops:
krdpass-auth-react-native(npm, all versions, GHSA-3j7p-44mj-76hx - React Native auth wrapper name-grab) and PyPItelegram-helper@0.1.1/0.1.2(GHSA-vxg4-4jxm-7ff9 - "starts a Telegram bot to exfiltrate sensitive session files and cookies", executes remote commands, steals browser data). The PyPI drop is the more actionable of the two - it is a confirmed infostealer, not just install-time reconnaissance
What to do
- 1Grep every
package-lock.json,yarn.lock,pnpm-lock.yaml,package.json,requirements.txt,poetry.lock, andPipfile.lockin your org for the names below. Uninstall on hit and rebuild the lockfile against a clean cache - 2For Cluster A hits (confirmed IOCs): audit DNS logs for queries to
*.oast.onlinebetween 2026-09-07 and now; audit HTTP egress logs for connections to5.189.159.252. Any host with a matching DNS or egress record is confirmed compromised - rotate every credential the host had access to (npm tokens, cloud IAM, SSH keys, git credentials, SSO), reimage, forensicate. Blockoast.onlineand5.189.159.252at your egress proxy - 3For Cluster B/C/D lockfile hits: treat the resolving host as fully compromised per GHSA boilerplate. Rotate npm tokens, cloud IAM, SSH keys, git credentials, SSO; wipe
node_modules, delete the lockfile, rebuild against a clean cache. The same oast.online / 5.189.159.252 beacon shape should be assumed until each specific package is independently analyzed - 4For Coinbase, Air Canada, Medisend, OPAP, Swisscom, Optimizely, Fastly, MathWorks, SimpliSafe, Tidal, PayPal, Twilio, Afterpay, Ecobee, Aiven (Karapace), Glia, Jobber, BMC, Feishu/Lark, dbt Labs, Octopus Deploy, Jacksher, Caliperx, and any org whose internal namespace appears above: audit internal npm mirror resolution logs for any of the exact names below. Any resolution attempt against a public-registry version of an internal name is dep-confusion exposure regardless of whether the malware executed - the naming pattern proves an attacker enumerated your internal package inventory
- 5Explicit scoped-registry pinning in
.npmrc: for@aircanada/,@medisend/,@cp-shared-*/,@opap/,@jacksher/,@caliperx2/, and every other internal npm scope, add explicitregistry=lines to.npmrcand enforce them in CI. Never rely on bare unscoped names to resolve to an internal package - dep-confusion works by racing against the internal name over public npm - 6For every
npm installin CI, prefer--ignore-scriptsto block postinstall / preinstall payloads. This is the single highest-value mitigation against the Cluster A/B/C probe shape -preinstall.jsnever runs if scripts are disabled - 7For the 2026-09-08 PyPI
telegram-helperdrop: grep everyrequirements.txt,poetry.lock,Pipfile.lock, andpyproject.tomlfortelegram-helper. On hit, immediately triage the host as an infostealer victim: browser cookies, session files, and Telegram credentials are the primary theft targets. Wipe the host, rotate every session cookie and browser-stored password, and rotate Telegram sessions from a different device - 8Add all Cluster A/B/C/D names to internal private-registry (Verdaccio / Artifactory / Nexus) deny-lists for at least 30 days to prevent re-uploads under the same names by rotating operators
References
- GitHubGitHub Advisory Database - recent malware advisoriesgithub.com
- GitHubGHSA-4jpr-935q-33r2 - @caliperx2/components (Cluster A - full IOCs)github.com
- GitHubGHSA-hmhj-jhrj-285j - b2b-frontend-external-library (Cluster A - Swisscom OCE target)github.com
- GitHubGHSA-w6c3-rrw8-wxrx - @aircanada/components (Cluster B)github.com
- GitHubGHSA-wfxf-4cwg-r55p - @medisend/core (Cluster B)github.com
- GitHubGHSA-3f8m-gfc3-3g2m - @cp-shared-14/frontend-ui (Cluster B - OpenSSF Package Analysis)github.com
- GitHubGHSA-356g-cp7r-g5f5 - @opap/player-kyc-widget (Cluster B - OPAP KYC widget)github.com
- GitHubGHSA-994q-v55m-r2mw - @idkruan-10/dpd-depconf-probe (Cluster B - explicit dep-confusion probe)github.com
- GitHubGHSA-wpv4-wxrh-hvmh - openai-pr-reviewer (Cluster C)github.com
- GitHubGHSA-9cfc-3wfm-r8p5 - matlab-azure-devops-extension (Cluster C)github.com
- GitHubGHSA-mf8g-pqcc-wxfw - karapace-docs (Cluster C - Aiven Karapace target)github.com
- GitHubGHSA-8pfr-f8q3-mr5x - optimizely-starter-kit-for-fastly-compute (Cluster C)github.com
- GitHubGHSA-3j7p-44mj-76hx - krdpass-auth-react-native (Cluster E - 2026-09-08 fresh drop)github.com
- GitHubGHSA-vxg4-4jxm-7ff9 - pip telegram-helper (Cluster E - 2026-09-08 PyPI infostealer)github.com
- OpenSSFOpenSSF malicious-packages repositorygithub.com