GitHub Advisory malware sweep - 2026-09-18 late + 2026-09-19 (npm `algamil7x.xyz` DNS-OOB scope expansion `@shared-web/utils`/`@shared-web/assets`/`@shared-runtime/modules`/`@insiderintelligence/googleadmanager` day 2; `test89-auth`/`test890-auth`/`test899-auth`/`test8999-auth` dep-confusion probe siblings of yesterday`s `test89078-auth`; on-chain Ethereum-C2 `tailwindcss-form@<=0.5.1` + `tailwindcss-forms-ui@<=0.5.2` day 2 of `0xa322E5f3...`; `@sanzoffc/baileys@<=3.0.4` newsletter-follower + unpinned `@whiskeysockets/eslint-config` github ref; `chai-as-indexed@<=7.2.8` `ipcheck-hashed.vercel.app` full-`process.env` exfil + `new Function()` RCE; `x509-escaping@0.0.0-0.0.2/1.0.1` Burp Collaborator `oastify.com` recon; `internallib_v949`, `sinful`, `openmct-heatmap`, `ac-polyfills` CWE-506; pip `py-venv-doctor@0.1.0/0.1.1` full-env-var telemetry exfil; pip `google-cloud-datacatalog-lineage-producer-client@9999`/`99999999`/`0.2.7` google-cloud-* dep-confusion sentinel; npm `keroeltop@99.99.99` malicious-domain probe)
GHSA 2026-09-18 late + 2026-09-19: 4x npm @shared-* + @insiderintelligence/* scopes at sentinel 9.9.10 extend yesterdays algamil7x.xyz DNS-OOB campaign into fresh internal-lookalike scopes (day 2, same operator); 4x test89-auth dep-confusion probes continue the test89078-auth cluster; on-chain Ethereum-C2 tailwindcss-form typosquats republish under 0xa322E5f3... (day 2); chai-as-indexed POSTs the full process.env to ipcheck-hashed.vercel.app and evals the response; pip py-venv-doctor` exfils environment variables via a fake healthcheck telemetry channel.
- Incident type
- Advisory sweep. A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
- Detected by
- GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · amazon-inspector · kam193/bad-packages · jaschadub/compromised-packages-check
- Also known as
- 2026-09-19 GHSA npm+pip sweep · algamil7x.xyz DNS-OOB scope expansion (day 2, @shared-web/@shared-runtime/@insiderintelligence) · test89*-auth dep-confusion probe siblings (day 2) · tailwindcss-form/tailwindcss-forms-ui on-chain Ethereum C2 day 2 (0xa322E5f3...) · @sanzoffc/baileys newsletter-follower + unpinned github ref (Baileys wave day 4) · chai-as-indexed ipcheck-hashed.vercel.app full-env exfil + require-time RCE · x509-escaping Burp Collaborator OOB recon · py-venv-doctor full-env-var telemetry exfil · google-cloud-datacatalog-lineage-producer-client dep-confusion sentinel · keroeltop malicious-domain probe
- Ecosystems
- npmPyPI
- Packages tracked
- 20
What happened
Between roughly 2026-09-18 12:00 UTC and 2026-09-19 12:00 UTC, GitHub Advisory Database published 20 new malware advisories — 18 npm and 2 pip. Todays batch is dominated by continuations of the operator clusters catalogued yesterday: the algamil7x.xyz DNS-OOB operator is on day 2 with four fresh internal-lookalike scopes; the tailwindcss-form on-chain-C2 operator is on day 2 with two more typosquats reusing the same Ethereum sender address; the test89-auth dep-confusion pentest is on day 2 with four sibling packages; and the Baileys-wave ecosystem continues with a day 4 newsletter-follower (@sanzoffc/baileys). Two require-time RCE payloads (chai-as-indexed, one on-chain) and one full-env-var telemetry exfil (py-venv-doctor) elevate the batch severity to high`.
Cluster A - algamil7x.xyz DNS-OOB scope expansion (npm)
| Package | Version | GHSA | DNS prefix |
|---|---|---|---|
@shared-web/utils | 9.9.10 | GHSA-29f7-pqf4-c94j | swutils |
@shared-web/assets | 9.9.10 | GHSA-vmr9-5w3x-4v98 | @shared-web/assets (raw package name) |
@shared-runtime/modules | 9.9.10 | GHSA-g85c-jph7-8q4r | @shared-runtime/modules |
@insiderintelligence/googleadmanager | 9.9.10 | GHSA-76rx-jxhm-vhww | googleadmanager |
The primitive. Each package ships a package.json with scripts.install: node index.js. On npm install, the script loads a lib/core.js that resolves os.userInfo().username, os.hostname(), and process.cwd() basename via module.constructor._load (bypassing literal require() calls); domain names and API strings are stored as hex byte arrays in two per-package obfuscation files (lib/a9b3de.js+lib/f8a2cd.js, lib/a74d1f.js+lib/f63c0e.js, lib/c5df9a.js+lib/b4ce8f.js, lib/g7h8i9.js+lib/h8i9j0.js), reconstructed via String.fromCharCode at runtime. The reconstructed exfil chain is a DNS resolution query of the form <prefix>-<user>-<host>-<cwd>.<ts>.oob.algamil7x.xyz, and the operator sees the resolution in their authoritative DNS log.
Same operator as yesterdays @tink/tink-link-core@9.9.10` (Cluster D of 2026-09-18 sweep): same DNS zone (oob.algamil7x.xyz), same sentinel version (9.9.10), same hex-array obfuscation pattern, same module.constructor._load evasion. Yesterday impersonated Tink open-banking SDK; today four fresh internal-lookalike scopes (@shared-web/*, @shared-runtime/*, @insiderintelligence/*). Treat any 9.9.10-tagged internal-name lookalike as this operator until proven otherwise, and keep watching for day-3 expansion tomorrow.
Cluster B - test89*-auth dep-confusion probe siblings (npm)
| Package | Sentinel version | GHSA |
|---|---|---|
test89-auth | any | GHSA-7868-hxr7-g8r6 |
test890-auth | any | GHSA-xvpv-wq7p-548c |
test899-auth | any | GHSA-jf2q-w77c-99vv |
test8999-auth | any | GHSA-25wf-vfrc-2r82 |
Same operator as yesterdays test89078-auth@99.99.99` (Cluster D of 2026-09-18 sweep) — same preinstall: node index.js primitive, same DNS-OOB primitive against 31ee29fe-db68-4fd3-86a2-2b707b9e95f0.dnshook.site. GHSA published only the CWE-506 boilerplate on these four, but the naming lineage (four sequential numeric-suffix test89*-auth variants plus yesterdays test89078-auth`) is diagnostic: one dep-confusion pentest engagement iterating the numeric suffix in the same 48-hour window.
Cluster C - On-chain Ethereum-C2 tailwindcss-form* typosquats (day 2) (npm)
| Package | Version | GHSA | Same Ethereum sender |
|---|---|---|---|
tailwindcss-form | <=0.5.1 | GHSA-xhr7-h7hc-7785 | 0xa322E5f3D311D3080e9aDC2490Ef6f0121063e1a |
tailwindcss-forms-ui | <=0.5.2 | GHSA-fc5q-m33g-rp9c | 0xa322E5f3D311D3080e9aDC2490Ef6f0121063e1a |
Same Ethereum sender address as yesterdays tailwindcss-form-utils/-form-ui (Cluster C of 2026-09-18 sweep). Same primitive: impersonate @tailwindlabs/tailwindcss-forms, obfuscator.io control-flow-flattened string array, query multiple Ethereum JSON-RPC endpoints (eth.publicnode.com, eth.drpc.org, 1rpc.io/eth, eth-mainnet.public.blastapi.io, eth.blockscout.com) for transactions authored by the hardcoded sender, decompress the transaction data (gzip/inflate/brotli), reconstruct a JavaScript payload, and execute via child_process.spawn`. The EtherHiding pattern is being iterated aggressively — four packages across two days against the same on-chain sender. Every new transaction from that address is a fresh command pushed to every installed victim.
Cluster D - @sanzoffc/baileys Baileys-wave day 4 (npm)
@sanzoffc/baileys@<=3.0.4 (GHSA-grqc-r63w-6845). Continues the day 1 plogme (2026-09-16) → day 2 jexkcode (2026-09-17) → day 3 libsignal-hijack quad (Cluster A of 2026-09-18) Baileys wave.
Todays variant is a nuisance-tier newsletter-follower — reconstructs an obfuscated URL to https://raw.githubusercontent.com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json, uses WhatsApp GraphQL mutations (query_id: 7871414976211147) with a base64+XOR-decoded @newsletter JID (XOR key 23`) to subscribe the infected account to attacker-specified newsletters 40 seconds after invocation.
Additionally, the manifest declares @whiskeysockets/eslint-config as an unpinned github: source with most other dependencies pinned to wildcards — same RCE-surface primitive as yesterday`s Cluster A packages. So the effective posture is: a nuisance payload today, an RCE surface waiting for the operator to flip.
Cluster E - chai-as-indexed require-time full-process.env exfil + RCE (npm)
chai-as-indexed@<=7.2.8 (GHSA-727r-6hg5-947x, MAL-2026-16293). Masquerades as a chai assertion-library plugin (impersonates chai-as-promised). On require:
- Loads
./lib/initializeCaller - POSTs the full
process.envof the installers Node process to a base64-encoded endpoint:https://ipcheck-hashed.vercel.app/api/auth/13b72bec1d4f2ee1c661` - The response body is passed to
new Function('require', responseBody)and invoked with the realrequire
Full remote code execution on every load, and the exfil payload contains every environment variable — CI secrets, npm tokens, cloud provider credentials, database URLs. --ignore-scripts does not block this — it triggers on require, not on install. Egress-block ipcheck-hashed.vercel.app in CI.
Cluster F - x509-escaping Burp Collaborator OOB recon (npm)
x509-escaping@0.0.0-0.0.2/1.0.1 (GHSA-fq85-7xqm-cgj9, MAL-2025-889). preinstall: node index.js reads:
- Hostname, username, home directory
- DNS server config
- Working directory
/etc/passwd,/etc/hosts
POSTs the collected data to https://agumuj6lhw9yqopq6npl1nlgu70yorcg.oastify.com (a Burp Collaborator payload URL the operator owns). Pentest-shaped — no persistent payload, install-time only — but the exfil is real and the harvested data is now on an attacker-controlled Burp endpoint.
Cluster G - CWE-506 boilerplate takedowns (npm, likely dep-confusion probes)
| Package | GHSA | Notes |
|---|---|---|
internallib_v949 | GHSA-f863-m366-9cfm, GHSA-4qw5-jqr6-c4fj | internallib_v<number> dep-confusion sentinel |
sinful | GHSA-2xjj-r8mc-xpf6 | No published analysis |
openmct-heatmap | GHSA-qx52-2xq4-3x3v | NASA Open MCT extension impersonation |
ac-polyfills | MAL-2026-782 (OSV-only) | @ac/ac-* internal-scope dep-confusion |
GitHub Advisory Database boilerplate only ("any computer that has this package installed should be considered fully compromised. All secrets and keys stored on that computer should be rotated"). Treat as medium — likely dep-confusion probes shaped like this week`s other probes, awaiting published payload analysis.
Cluster H - pip py-venv-doctor full-env-var telemetry exfil
py-venv-doctor@0.1.0/0.1.1 (GHSA-94w6-hr49-qjm7, MAL-2026-16296, campaign 2026-09-py-venv-doctor). Overrides setup.py's install command to execute during pip install, then sends a "fake healthcheck report" telemetry channel that transmits the full environment variable set — including every sensitive variable in scope of pip install (CI secrets, cloud provider credentials, database URLs). Confirmed infostealer, not a probe.
Cluster I - pip google-cloud-datacatalog-lineage-producer-client google-cloud-* dep-confusion
google-cloud-datacatalog-lineage-producer-client@9999/99999999/0.2.7 (MAL-2024-12279). OSV-tracked from 2024 but freshly relisted in todays GitHub Advisory sweep. Three sentinel-tier version numbers on a plausibly-internal google-cloud-* name — classic dep-confusion resolution-attack lure against internal Google/GCP developer registries that mirror the google-cloud-*` namespace.
Cluster J - keroeltop@99.99.99 malicious-domain probe (npm)
keroeltop@99.99.99 (GHSA-gg5m-rqpp-c9xf, MAL-2026-16297). OpenSSF Package Analysis flag only: "The package communicates with a domain associated with malicious activity." Single sentinel version, no detailed payload disclosure yet — treat as medium pending IOC publication.
Cross-operator patterns worth flagging
- The
algamil7x.xyzoperator is on day 2. Yesterday one package, today four — the operator is scaling. Block the DNS zone at your resolver; expect day 3 tomorrow. - *The `tailwindcss-form
on-chain operator is on day 2** and still using the same0xa322E5f3...` Ethereum sender. Detection cost stays asymmetric: no domain to block, only outbound Ethereum-RPC traffic from build environments to alert on. - *The `test89-auth
engagement is on day 2** with four numeric-suffix siblings of yesterdaystest89078-auth. Same DNS hook, same primitive. - The Baileys wave is on day 4 and now includes both nuisance newsletter-followers and full install-time RCE via unpinned
github:dependencies. Treat any Baileys wrapper as suspect. chai-as-indexedis a require-time full-process.envexfil + RCE — the highest-severity single package in todays batch. Every environment variable the parent Node process could see is on the operators server.
Registry state
All packages above are flagged as malware on npm and PyPI and quarantined at the time of writing. Private mirrors that cached tarballs before quarantine keep serving the malicious versions; network-edge egress blocks on oob.algamil7x.xyz, dnshook.site, ipcheck-hashed.vercel.app, oastify.com, and outbound Ethereum-JSON-RPC calls from CI are the durable mitigations.
Discovery credits
GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, amazon-inspector, kam193/bad-packages, jaschadub/compromised-packages-check. Per-package IOC details drawn verbatim from GHSA advisory bodies published between 2026-09-18 12:00 UTC and 2026-09-19 12:00 UTC.
Affected packages (20)
- npm@insiderintelligence/googleadmanager9.9.10
- npm@sanzoffc/baileys<=3.0.4
- npm@shared-runtime/modules9.9.10
- npm@shared-web/assets9.9.10
- npm@shared-web/utils9.9.10
- npmac-polyfills>=0
- npmchai-as-indexed<=7.2.8
- PyPIgoogle-cloud-datacatalog-lineage-producer-client9999999999990.2.7
- npminternallib_v949>=0
- npmkeroeltop99.99.99
- npmopenmct-heatmap>=0
- PyPIpy-venv-doctor0.1.00.1.1
- npmsinful>=0
- npmtailwindcss-form<=0.5.1
- npmtailwindcss-forms-ui<=0.5.2
- npmtest89-auth>=0
- npmtest890-auth>=0
- npmtest899-auth>=0
- npmtest8999-auth>=0
- npmx509-escaping0.0.00.0.10.0.21.0.1
These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.
Impact
- Cluster A — 4x npm
algamil7x.xyzDNS-OOB scope expansion (day 2 of yesterday`s Cluster D operator):@shared-web/utils@9.9.10(GHSA-29f7-pqf4-c94j, MAL-2026-16292),@shared-web/assets@9.9.10(GHSA-vmr9-5w3x-4v98, MAL-2026-16283),@shared-runtime/modules@9.9.10(GHSA-g85c-jph7-8q4r, MAL-2026-16291),@insiderintelligence/googleadmanager@9.9.10(GHSA-76rx-jxhm-vhww, MAL-2026-16290). All four declarescripts.install: node index.js; the install script loadslib/core.jswhich resolvesos.userInfo().username,os.hostname(), andprocess.cwd()basename, then DNS-resolves subdomains ofoob.algamil7x.xyz(the same zone yesterdays@tink/tink-link-core@9.9.10exfiltrated to). Uniform code style:String.fromCharCodehex-array obfuscation in two per-packagelib/<random>.jsfiles,module.constructor._loadused in place of literalrequire(), prefix each package chooses (swutils,@shared-runtime/modules,@shared-web/assets,googleadmanager) is the campaign identifier the operator sees in their authoritative DNS log. **Day 2 of the same operator: yesterday@tink/tink-link-core(Tink open-banking SDK impersonation), today four fresh internal-lookalike scopes** — treat any9.9.10`-tagged internal-name lookalike as this operator until proven otherwise - *Cluster B — 4x npm `test89-auth
dep-confusion probe siblings**:test89-auth(GHSA-7868-hxr7-g8r6, MAL-2026-16288),test890-auth(GHSA-xvpv-wq7p-548c, MAL-2026-16289),test899-auth(GHSA-jf2q-w77c-99vv, MAL-2026-16285),test8999-auth(GHSA-25wf-vfrc-2r82, MAL-2026-16286). Same operator as yesterdaystest89078-auth@99.99.99(Cluster D of 2026-09-18 sweep), same preinstall pattern, same DNS-OOB primitive against31ee29fe-db68-4fd3-86a2-2b707b9e95f0.dnshook.site. GHSA carries only the CWE-506 boilerplate for these four, but the naming lineage (four sequentialtest89-,test890-,test899-,test8999-, and yesterdaystest89078-`) is diagnostic: this is one dep-confusion pentest engagement iterating the numeric suffix. Pentest-shaped, but the payload nevertheless exfils hostname/username to a public DNS-OOB service — treat installs as intelligence-gathering hits - *Cluster C — 2x npm on-chain Ethereum-C2 `tailwindcss-form
typosquats (day 2 of yesterdays Cluster C operator):tailwindcss-form@<=0.5.1(GHSA-xhr7-h7hc-7785) andtailwindcss-forms-ui@<=0.5.2(GHSA-fc5q-m33g-rp9c, MAL-2026-16295). Same primitive as yesterdaystailwindcss-form-utils/-form-ui(Cluster C of 2026-09-18): impersonate@tailwindlabs/tailwindcss-forms, obfuscator.io string-array with control-flow flattening, query multiple Ethereum JSON-RPC endpoints (eth.publicnode.com,eth.drpc.org,1rpc.io/eth,eth-mainnet.public.blastapi.io,eth.blockscout.com), pull txlist for transactions authored by the hardcoded sender0xa322E5f3D311D3080e9aDC2490Ef6f0121063e1a, decompress the transaction data (gzip/inflate/brotli), reconstruct a JavaScript payload, and execute viachild_process.spawn`. This is the same Ethereum address as yesterday`s pair** — the same on-chain command channel is now four packages deep across two days, and the EtherHiding pattern is being iterated aggressively - Cluster D — 1x npm
@sanzoffc/baileys@<=3.0.4newsletter-follower + unpinned github: RCE surface (day 4 of Baileys wave): GHSA-grqc-r63w-6845. Continues theplogme(2026-09-16) →jexkcode(2026-09-17) → yesterdays libsignal-hijack quad (Cluster A of 2026-09-18) Baileys wave. This one is a nuisance-tier newsletter-follower: reconstructs an obfuscated URL tohttps://raw.githubusercontent.com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json, uses WhatsApp GraphQL mutations (query_id: 7871414976211147) with a base64+XOR-decoded@newsletterJID (XOR key23) to subscribe the infected account to attacker-specified newsletters 40 seconds after invocation. Additionally, the manifest declares@whiskeysockets/eslint-configas an unpinned github: source — same RCE-surface primitive as yesterdays Cluster A packages. Ship it as day 4 of the Baileys wave - Cluster E — 1x npm
chai-as-indexed@<=7.2.8require-time RCE viaipcheck-hashed.vercel.app: GHSA-727r-6hg5-947x, MAL-2026-16293. Masquerades as achaiassertion-library plugin (impersonateschai-as-promisednaming). On require, POSTs the entireprocess.envof the installers Node process (every environment variable — CI secrets, npm tokens, cloud provider credentials) to a base64-encoded endpointhttps://ipcheck-hashed.vercel.app/api/auth/13b72bec1d4f2ee1c661(base64:aHR0cHM6Ly9pcGNoZWNrLWhhc2hlZC52ZXJjZWwuYXBwL2FwaS9hdXRoLzEzYjcyYmVjMWQ0ZjJlZTFjNjYx). The response body is passed tonew Function('require', responseBody)and invoked with the realrequire`, enabling arbitrary remote code execution on every load — not just install-time - Cluster F — 1x npm
x509-escapingBurp Collaborator OOB recon: GHSA-fq85-7xqm-cgj9, MAL-2025-889.x509-escaping@0.0.0-0.0.2+1.0.1. Preinstall:node index.js; the script harvests hostname, username, home directory, DNS server, working directory, plus reads/etc/passwdand/etc/hosts, then POSTs the data tohttps://agumuj6lhw9yqopq6npl1nlgu70yorcg.oastify.com(Burp Collaborator payload URL). Same posture asx509-escapingand other-escaping-family reconnaissance packages: dep-confusion tactic, install-time only, pentest-shaped but the harvested data is on a Burp Collaborator endpoint the operator owns - Cluster G — 4x npm CWE-506 boilerplate takedowns (no published analysis; likely dep-confusion probes):
internallib_v949(GHSA-f863-m366-9cfm, GHSA-4qw5-jqr6-c4fj, MAL-2026-16294) — the name pattern (internallib_v<number>) is a canonical dep-confusion sentinel;sinful(GHSA-2xjj-r8mc-xpf6, MAL-2026-16284);openmct-heatmap(GHSA-qx52-2xq4-3x3v, MAL-2026-16287) — impersonation of NASAs Open MCT visualisation extensions;ac-polyfills(MAL-2026-782 — OSV-only, no GHSA at the time of writing) — dep-confusion of the@ac/ac-*internal scope pattern. All four flagged by GitHub Advisory Database with only the CWE-506 boilerplate warning ("any computer that has this package installed should be considered fully compromised. All secrets and keys stored on that computer should be rotated"). Treat asmedium` pending published payload analysis - Cluster H — pip
py-venv-doctor@0.1.0/0.1.1full-env-var telemetry exfil: GHSA-94w6-hr49-qjm7, MAL-2026-16296 (campaign2026-09-py-venv-doctor). Overridessetup.py'sinstallcommand to execute duringpip install, then posts a "fake healthcheck report" telemetry channel that transmits "the full environment variable set, including any sensitive variables". Confirmed infostealer, not a probe. Same operator-shaped pattern as this weeksrequests-*@2.34.2` setup.py-override cluster - *Cluster I — pip
google-cloud-datacatalog-lineage-producer-client@9999/99999999/0.2.7google-cloud- dep-confusion*: MAL-2024-12279 (OSV-only, backfilled to 2026-09-18 sweep). Three sentinel-tier version numbers on a plausibly-internal google-cloud- name — classic dep-confusion resolution-attack lure targeting any internal Google/GCP developer registry that mirrorsgoogle-cloud-*names. The9999/99999999combo is a hallmark of the same operator that has been publishinggoogle-cloud-*dep-confusion probes since at least 2024 - Cluster J — 1x npm
keroeltop@99.99.99malicious-domain probe: GHSA-gg5m-rqpp-c9xf, MAL-2026-16297. OpenSSF Package Analysis flag: "The package communicates with a domain associated with malicious activity." Single sentinel version99.99.99, no detailed payload disclosure at time of writing. Treat asmediumpending IOC publication
What to do
- 1Grep every
package-lock.json,yarn.lock,pnpm-lock.yaml,package.json,requirements.txt,Pipfile.lock, andpoetry.lockin your org for every package name in Clusters A through J. Uninstall on hit, wipenode_modules/.venv, delete the lockfile, rebuild against a clean cache. Clusters A, B, C, D, E, F, H include real payloads (DNS exfil, on-chain RCE, require-time env var exfil, Burp Collab OOB recon, install-time env var telemetry) — a hit is a compromise, not a warning - 2*For Cluster A (
algamil7x.xyzscope expansion) + Cluster B (`test89-authdep-confusion)**: any host thatnpm installed@shared-web/utils,@shared-web/assets,@shared-runtime/modules,@insiderintelligence/googleadmanager,test89-auth,test890-auth,test899-auth, ortest8999-authDNS-resolved a label carrying hostname/username. Rotate credentials accessible from that host, blockoob.algamil7x.xyzand31ee29fe-db68-4fd3-86a2-2b707b9e95f0.dnshook.siteat your resolver, and if you maintain internal@shared-web,@shared-runtime,@insiderintelligence, ortest89*scopes, pin them to your internal registry with.npmrcand configure the internal registry to refuse public-npm publishes under the same names. Sentinel versions9.9.10and99.99.99` are classic dep-confusion resolution-attack markers - 3*For Cluster C on-chain-C2 `tailwindcss-form
(day 2)**: no domain to block — the command channel is Ethereum mainnet transactions from0xa322E5f3D311D3080e9aDC2490Ef6f0121063e1a. Detection: alert on anychild_process.spawnin a build environment, alert on outbound TCP to*.publicnode.com,eth.drpc.org,1rpc.io,eth-mainnet.public.blastapi.io, and blockscout instances from build environments (these should never appear in a legitimate frontend build), and pin@tailwindcss/forms` (correct name) explicitly in every project — the four typosquats span two days and are ranking in npm search results - 4For Cluster D
@sanzoffc/baileys: uninstall on hit, note that any connected WhatsApp account with the package running silently subscribes toskyzopedia/NewsletterID/VIP_Push.jsonnewsletter list 40 seconds after invocation. Additionally, the unpinnedgithub:dependency on@whiskeysockets/eslint-configgrants install-time RCE surface — audit that host as if it had run arbitrary code. Extend your registry denylist to any Baileys wrapper you have not personally vetted - 5For Cluster E
chai-as-indexed:--ignore-scriptsdoes NOT block this — it triggers onrequire. Any Node process that loaded this package POSTed its completeprocess.env(every environment variable) toipcheck-hashed.vercel.app/api/auth/13b72bec1d4f2ee1c661. Assume every environment variable the process could see (CI secrets, npm tokens, AWS/GCP/Azure creds, database URLs) is compromised, and rotate all of them. Blockipcheck-hashed.vercel.appat CI egress - 6For Cluster F
x509-escaping: uninstall, rotate credentials, blockoastify.com(Burp Collaborator) at CI egress. Any host that installed the package exfiltrated/etc/passwd,/etc/hosts, DNS server config, hostname, and username to a Burp Collaborator subdomain the operator owns. Even if legitimate red-team, treat the exfil as harvested until you know otherwise - 7For Cluster G CWE-506 boilerplate takedowns: uninstall on hit, rotate env values as a precaution. These are pending published analysis — treat any of them as install-and-forget malware until a vendor publishes IOCs. Consider extending your registry denylist to
internallib_*,openmct-*,ac-polyfills - 8For Cluster H
py-venv-doctor:pip uninstall py-venv-doctor. The install-time payload exfiltrated the entire environment-variable set to the operator; rotate every credential visible topip installin that environment. Addpip install --no-binary :all: --isolatedto CI where possible to block setup.py-side attack paths - 9For Cluster I
google-cloud-datacatalog-lineage-producer-client: if you maintain an internalgoogle-cloud-*package under this exact name, pin it to your internal registry and refuse public-PyPI publishes under the same name. The9999/99999999sentinel-version pair is the classic dep-confusion resolution attack against internal mirrors - 10For Cluster J
keroeltop: uninstall on hit, rotate credentials. IOC disclosure is pending — assume the sentinel version99.99.99behaves like other dep-confusion probes until analysis publishes - 11For every
npm installin CI, prefer--ignore-scriptsor an equivalent lockfile-consumer mode that blocks pre/post-install hooks. This blocks Clusters A, B, F, and H at install; but does NOT block Cluster C (require-time on-chain), Cluster D (require-time GraphQL), or Cluster E (require-time RCE). Layer with egress denylists onoob.algamil7x.xyz,dnshook.site,ipcheck-hashed.vercel.app,oastify.com,webhook.site, and*.publicnode.com/drpc.org/1rpc.io/eth.blockscout.com/eth-mainnet.public.blastapi.io(or, for legitimate Web3 workloads, alert-only on Ethereum RPCs from build environments) - 12Add every specific package name below to your internal private-registry deny-list for at least 30 days. Extend your existing pin-lists with
@shared-web/*,@shared-runtime/*,@insiderintelligence/*,@sanzoffc/baileys,test89*-auth,chai-as-*,openmct-*,internallib_*,ac-polyfills,keroeltop,x509-escaping,google-cloud-datacatalog-lineage-producer-client,py-venv-doctor, and any Baileys wrapper you have not personally vetted
References
- GitHubGitHub Advisory Database - recent malware advisoriesgithub.com
- GitHubGHSA-gg5m-rqpp-c9xf - keroeltop (Cluster J - malicious-domain probe)github.com
- GitHubGHSA-94w6-hr49-qjm7 - py-venv-doctor (Cluster H - pip full-env-var telemetry exfil)github.com
- GitHubGHSA-29f7-pqf4-c94j - @shared-web/utils (Cluster A - algamil7x.xyz DNS-OOB day 2)github.com
- GitHubGHSA-vmr9-5w3x-4v98 - @shared-web/assets (Cluster A)github.com
- GitHubGHSA-g85c-jph7-8q4r - @shared-runtime/modules (Cluster A)github.com
- GitHubGHSA-76rx-jxhm-vhww - @insiderintelligence/googleadmanager (Cluster A)github.com
- GitHubGHSA-7868-hxr7-g8r6 - test89-auth (Cluster B - dep-confusion probe siblings)github.com
- GitHubGHSA-xvpv-wq7p-548c - test890-auth (Cluster B)github.com
- GitHubGHSA-jf2q-w77c-99vv - test899-auth (Cluster B)github.com
- GitHubGHSA-25wf-vfrc-2r82 - test8999-auth (Cluster B)github.com
- GitHubGHSA-xhr7-h7hc-7785 - tailwindcss-form (Cluster C - on-chain ETH C2 day 2)github.com
- GitHubGHSA-fc5q-m33g-rp9c - tailwindcss-forms-ui (Cluster C)github.com
- GitHubGHSA-grqc-r63w-6845 - @sanzoffc/baileys (Cluster D - Baileys wave day 4)github.com
- GitHubGHSA-727r-6hg5-947x - chai-as-indexed (Cluster E - ipcheck-hashed.vercel.app env exfil + RCE)github.com
- GitHubGHSA-fq85-7xqm-cgj9 - x509-escaping (Cluster F - Burp Collab OOB recon)github.com
- GitHubGHSA-f863-m366-9cfm - internallib_v949 (Cluster G - CWE-506 boilerplate)github.com
- GitHubGHSA-2xjj-r8mc-xpf6 - sinful (Cluster G)github.com
- GitHubGHSA-qx52-2xq4-3x3v - openmct-heatmap (Cluster G)github.com
- jaschadubjaschadub/compromised-packages-check - Sep 18-19 2026 sweepgithub.com
- OpenSSFOpenSSF malicious-packages repositorygithub.com