Feed
HighPublished 6 Jul 2026162 packages · 429 versions

GitHub Advisory malware sweep - ~155 npm packages (logger/tailwind/eslint/bignumber typosquats, polymarket-onchain-* crypto-drainers) taken down 2026-07-06

Summary

On 2026-07-06 GitHub's Advisory Database published ~155 CWE-506 Embedded Malicious Code advisories against npm packages - the largest single-day 2026 GHSA npm-malware sweep to date. The batch clusters into six naming families: chalk/pino/winston/*-logger pretty-print typosquats, tailwindcss/vite typosquats, eslint / *-lint-* helper squats, bignumber.js / crypto-math typosquats, chai *-as-* matcher squats, and two polymarket-onchain-* crypto-drainer slugs continuing the June cluster. npm replaced every name with 0.0.1-security.

typosquatcredential-theftcrypto-wallet-drain
Detected by
GitHub Advisory Database · npm Security
Also known as
2026-07-06 GHSA npm sweep
Ecosystems
npm
Packages tracked
162

What happened

On 2026-07-06 GitHub's Advisory Database published ~155 CWE-506 (Embedded Malicious Code) advisories against npm packages - a single-day volume that dwarfs the individual mid-week sweeps (2026-06-30 - 5 packages, 2026-07-02 - 9 packages, 2026-07-03 - 14 packages) and appears to represent a bulk backlog processing action by GHSA staff. Every record uses the standard "any computer that has this package installed or running should be considered fully compromised - rotate all secrets from a different computer" boilerplate. No payload write-ups accompany any of the GHSA texts.

Six naming clusters

1. Logger / pretty-print typosquats (~34 packages)

A sprawling cluster targeting the Node.js structured-logging vocabulary. pino-utils, pino-formatter, pino-sdk-v2, pino-pretty-logs, pretty-pino-logger, pretty-pino-loggers collide with the pino family. winston-prism, winston-js-express collide with winston. chalki-pretty, chalk-pro-logger, chalks-logger, chalk-logger-prettier, chalk-prettier, chalk-plus-ts collide with chalk + prettier. Add picocolor-logger, custom-log-viewer, color-cli-log, color-logger-console, logger-beauty, awesome-cli-logger, emojiprint-logger, emojiprint-prettier, styled-text-logger, log-format-thread, log-upgrade, elevate-log, sleek-pretty, prettier-logger. Every one of these is a plausible mistype or "prettier fork" that would slip past a lockfile review that only checks for exact-match brand names.

2. Tailwind / Vite / PostCSS typosquats (~11 packages)

Continuation of the 2026-07-02 sweep Tailwind theme. tailwindcss-animatecss-latest@2.1.02.1.1, tailwindcss-fonttypo-inter@2.3.2, tailwindcss-fonttype-inter@2.3.12.3.2, tailwindcss-svg-helper@1.17.91.18.0, tailwindcss-framer-motion@1.1.3, tailwind-typography-plus@2.1.0, tailwind-fonttype-inter@2.3.2, tailwind-scroller@1.0.2. Vite: vite-plugin-svg-paths@1.1.51.1.9, vite-plugin-compress-js@0.5.40.5.7, vite-config-field@1.1.01.1.5.

3. ESLint / lint-helper typosquats (~20 packages)

ts-eslinter, ts-lint-builds, ts-lint-builders, ts-eslint-helper, bjs-lint-builder, bjs-lint-builders, sjs-lint-build1, hjs-lint-builders, es-lint-entry, es-lint-builders, eslint-vite, eslint-helper, lint-null, lint-nule, lint-nuler, lint-builds, lint-builders, linter-entry, npm-eslint-helper, test-prettier. Naming pattern is a rebranding operator cycling through single-letter prefixes (bjs-, sjs-, hjs-, cjs-, mjs-) - same shape as the 2026-07-03 SQL cluster.

4. bignumber.js / crypto-math typosquats (~17 packages)

bigint.os, bigint.fs, bn-eslint.js, bn-math, ether-bn.js, next-bignumber.js, big-numerator, big-numer, big-numerate, big256-ts, and the prefixed set sjs-biginteger, mjs-biginteger, cjs-biginteger, bjs-biginteger, hjs-biginteger, st-biginteger, st-bigintr. Almost all versions cluster around 5.0.5+ - the same starting version as the real bignumber.js, giving the fakes a plausible "current version" if a developer skims npm search results.

5. Chai *-as-* matcher squats (5 packages)

chai-guard, chai-dec, chai-as-init, chai-as-polished, chai-as-decrypted. All plausibly typo chai-as-promised, the canonical async-assertion adapter. Same batch also includes test-prettier (fake Jest/Mocha helper).

6. Polymarket crypto-drainer continuation (2 packages)

polymarket-onchain-sdk@1.0.21.0.4 and polymarket-onchain-plugin@2.1.32.1.5 continue the Polymarket brand-collision campaign tracked from 2026-06-27's polymarket-clob-math package. Same brand, different slugs - indicative of a persistent operator working the Polymarket wallet-drainer angle across weeks.

7. Miscellaneous (~65 packages)

The remainder is a long tail of individual typosquats and throwaway names: argonflux, modulyn, syncora, stacknova, graphpilot, bytecore, peptideenv, fastnodemailer, bubblestr, subsearch, windrule-utils, typedecode, twcompose-utils, txs-data, theta-connector, theta-kit, tailstyle-core, rma-utils, sol-sdk, secure-box, set-proto-chain, router-kit, request-js-validator, react-svg-render, react-check-error, react-native-template-my-starter, react-next-dom, rollup-plugin-polyfill-handler, webpack-patch, webpack-cache-clean, motion-lib, df-vision, debug-glitzs, mongoose-json-format, mongoose-lean-hooks, metrica-node, metrica-chain, js-unimode, jsontoken-extend, jsonupper, js-crypto-promise, older_morgan, chain-await-test, bootstrap-utils, competion, btd-smart, cookie-ease, safe-validate, renderctx, classbreeze-utils, grid-settings-align, env-axios, environment-gate, express-guardrail, express-session-js, express-initial, express-dotenv, dotenv-express, db-query-log, devkit-scripts, eth-tick, eth-logger, node-env-detector, nodepathbalance54, normalize-path-seq, ts-webplug, ts-build-optimize, ts-bigtn, ts-relayer-pub, tsliverhome, npm-doc-dev, @jaime9008/math-service, xnder-sdk-js, web-pool, wime-zle, unique-id-64, random-string-64. Some carry unusually long publish histories (js-unimode 10 versions, jsontoken-extend 14 versions, df-vision 12 versions, cookie-ease 10 versions, router-kit 30+ versions) - signals of long-running operator persistence that GHSA has now cleaned up in one shot.

Registry state

Every package now resolves to a 0.0.1-security holding tarball owned by npm Security. Historical version tarballs may remain fetchable from the CDN as of 2026-07-07 and should be treated as live malware in any lockfile hit - the CDN retention window for withdrawn npm versions typically runs 24–72 hours after the security replacement lands.

Affected packages (162)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • Any host that installed any of the ~155 packages listed below should be treated as fully compromised - every GHSA record uses the boilerplate "rotate all secrets from a different computer" language; no patched version exists for any of them
  • The polymarket-onchain-sdk@1.0.21.0.4 and polymarket-onchain-plugin@2.1.32.1.5 names continue the crypto-wallet-drainer campaign already tracked under polymarket-clob-math - same brand collision, different slugs, likely same operator
  • The logger / pretty-print family (pino-*, winston-*, chalk-*, picocolor-logger, chalki-pretty, prettier-logger, styled-text-logger, sleek-pretty, emojiprint-*, logger-beauty, color-cli-log, color-logger-console, awesome-cli-logger, elevate-log, custom-log-viewer) squats the entire Node.js structured-logging naming space - 30+ distinct package names targeting the exact vocabulary a developer types when adding logging to a service
  • The bignumber.js / crypto-math cluster (bigint.os, bigint.fs, bn-eslint.js, bn-math, ether-bn.js, next-bignumber.js, big-numerator, big-numer, big-numerate, big256-ts, sjs-biginteger, mjs-biginteger, cjs-biginteger, bjs-biginteger, hjs-biginteger, st-biginteger, st-bigintr) targets developers who typo the ubiquitous bignumber.js slug used across Ethereum/Solana tooling - many hit 5.0.5+ versions to blend with bignumber.js's own version range
  • The tailwindcss / vite typosquat cluster (tailwindcss-animatecss-latest, tailwindcss-fonttypo-inter, tailwindcss-fonttype-inter, tailwindcss-svg-helper, tailwindcss-framer-motion, tailwind-typography-plus, tailwind-fonttype-inter, tailwind-scroller, vite-plugin-svg-paths, vite-plugin-compress-js, vite-config-field) continues the Tailwind/Animate.css / Vite plugin theme from the 2026-07-02 sweep - the same operator or a copycat is still working the same aesthetic naming space
  • The chai *-as-* matcher cluster (chai-guard, chai-dec, chai-as-init, chai-as-polished, chai-as-decrypted) plausibly squats chai-as-promised, the canonical assertion adapter for async Chai tests - anyone adding an async matcher to a test suite between publish and 2026-07-06 could have grabbed one of these

What to do

  1. 1Grep your lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml) for every name in the packages map below - 155+ names is too many to eyeball. Any match is a supply-chain incident: rotate every credential the build runner could reach and re-image the build host
  2. 2If you resolved polymarket-onchain-sdk or polymarket-onchain-plugin at any point: treat this as a crypto-wallet compromise. Any wallet key, seed phrase, or exchange API key that touched that machine should be rotated immediately and funds moved
  3. 3Add the pino-, winston-, chalk-, tailwindcss-, vite-plugin-, bignumber.js / big-* / bigint.*, eslint-, lint-, and chai-as-* name prefixes to a review gate on any package addition - the malware operators have been farming these exact naming spaces for three consecutive months
  4. 4Verify none of the 155+ listed packages still resolves via your private mirror - internal Artifactory / Nexus / Verdaccio instances routinely cache tarballs and will keep serving the malicious versions after the public yank
  5. 5For the ESLint / TypeScript-lint family (ts-lint-builds, ts-lint-builders, ts-eslinter, ts-eslint-helper, bjs-lint-*, hjs-lint-*, sjs-lint-*, es-lint-*, lint-builds, lint-builders, lint-null, lint-nule, lint-nuler, linter-entry): none of these are legitimate ESLint or TypeScript packages. The canonical slugs are eslint, @typescript-eslint/eslint-plugin, typescript-eslint
  6. 6If your build ever resolved a *jsonupper / js-crypto-promise / js-unimode / jsontoken-extend name: these are placeholder utility slugs common to malware operators; the mainstream JSON/JWT/promise-utility names (json5, jsonwebtoken, p-map, etc.) do not use these suffixes

References

npm-2026-07-06-ghsa-malware-sweep