GitHub Advisory npm CWE-506 sweep - 28-package late 2026-07-29 backfill (`@ai-plus`/`@ai-agent-node` 5-pkg AI-agent SDK cluster, 5-pkg Polymarket / prediction-market impersonator kit, `@peptide-unit` scope pair, 6-pkg Alibaba-adjacent `lzd-*`/`uniapi-*`/`aone-cloud-cli`/`colder-cli`/`lwp-web-client`/`def-open-client` scope, `@zannstore/baileys` 17-version WhatsApp SDK typosquat, misc single-package RATs including `eslintcmd` ESLint typosquat)
GitHub Advisory Database published a further 28 npm CWE-506 advisories dated 2026-07-29 after the prior day's ingest - clusters: @ai-plus/@ai-agent-node 5-pkg AI-agent SDK scopes, 5-pkg Polymarket / prediction-market impersonator kit (polymarket-risk-manager, poly-kelly, ts-precision, ts-bn-proto, stake-math), @peptide-unit pair, 6-pkg Alibaba-adjacent scope, @zannstore/baileys 17-version WhatsApp SDK typosquat.
- Detected by
- GitHub Advisory Database · OpenSSF Package Analysis · npm Security
- Also known as
- 2026-07-29 late GHSA npm backfill · Polymarket prediction-market impersonator kit · @ai-plus / @ai-agent-node AI-agent SDK cluster · @peptide-unit biotech scope pair · @zannstore/baileys WhatsApp SDK typosquat
- Ecosystems
- npm
- Packages tracked
- 28
What happened
On 2026-07-29 (published throughout the day, largely AFTER the npm-2026-07-29-ghsa-malware-sweep module was authored earlier the same UTC day), the GitHub Advisory Database published a further 28 new npm CWE-506 (Embedded Malicious Code) advisories. This module catalogues that late-day 2026-07-29 backfill batch - the prior module's "2026-07-29 batch (6 packages)" only saw the 6 that were live at the time it was authored.
The 28-package batch has clear operator-cluster structure - coordinated same-scope publishes, thematically-grouped naming, and same-day CWE-506 boilerplate signatures - indicating four coordinated multi-package campaigns and a scatter of single-package RATs, rather than 28 unrelated hobbyist typosquats.
Cluster A - @ai-plus/* + @ai-agent-node/* AI-agent SDK impersonation scopes (5 packages, all >= 0, all 2026-07-29)
| Package | Notes | |---|---| | @ai-plus/de-agent-sdk | "de-agent" SDK impersonation | | @ai-plus/de-agent | matching non-SDK entry | | @ai-agent-node/createnode | agent-node factory impersonation | | @ai-agent-node/agent-node | scope-root brand impersonation | | @ai-agent-node/nodesql | agent-node SQL integration impersonation |
Two coordinated attacker-owned scopes publishing under generic AI-agent-tooling names in the same 24h window. Same-day, same-CWE-506 boilerplate, same all-versions signature - probable single-operator running scope-diverse AI-agent-adjacent malware to catch developers experimenting with agent-SDK integrations. Consistent with the broader 2026 AI-tooling supply-chain-attack surface previously catalogued in npm-2026-02-17-cline-clinejection, multi-2026-04-29-promptmink-validate-sdk, and npm-2026-04-15-kindo-selfbot-xworm.
Cluster B - Polymarket / prediction-market tooling impersonator kit (5 packages, all >= 0, all 2026-07-29)
| Package | Notes | |---|---| | polymarket-risk-manager | Polymarket risk / position-sizing impersonation | | poly-kelly | Kelly-criterion bet-sizing (Polymarket trading bots) | | ts-precision | bn.js-precision math impersonation | | ts-bn-proto | bn.js prototype impersonation | | stake-math | staking / DeFi position-math impersonation |
Names read as a coordinated set: risk-manager + Kelly-criterion + precision math + big-number arithmetic + staking math - all mathematical primitives a Polymarket / CLOB trading bot would import. Same-day publish across all five is a strong single-operator signal. Extends the operator space around npm-2026-07-17-polymarket-trap-clob-client-math (@polymarket/clob-client math wrappers) and the June polymarket-clob-math-vercel-loader cluster. Treat any hit on a host running Polymarket trading bots as a full crypto-wallet-compromise event.
Cluster C - @peptide-unit/* biotech / chemistry scope pair (2 packages, all >= 0, all 2026-07-29)
| Package | Notes | |---|---| | @peptide-unit/peptide-modify | peptide-modification tool impersonation | | @peptide-unit/js-unimode | nonsense-name paired publish |
Coordinated same-scope publish under domain-specific-sounding biotech names. The js-unimode sibling is telling - a nonsense name paired with a plausibly-domain-specific name is classic dep-confusion probe signature against an internal peptide-analysis library namespace at a biotech / pharma customer.
Cluster D - Alibaba-adjacent Lazada / uni-app / Aone scope (6 packages, all >= 0, all 2026-07-29)
| Package | Notes | |---|---| | lzd-unified-station-sdk | Lazada (lzd) unified-station seller-central SDK impersonation | | uniapi-bridge | uni-app (Vue-based Alibaba cross-platform framework) SDK bridge | | aone-cloud-cli | Alibaba Aone DevOps CLI - extends 07-28 aone-kit / aone-kit-cli / aone-sandbox cluster | | colder-cli | generic CLI, Alibaba-scope naming | | lwp-web-client | web-client impersonation, Alibaba-scope naming | | def-open-client | open-client impersonation, Alibaba-scope naming |
All six flagged all-versions, no patched builds. Consistent with dep-confusion probes against Alibaba / Lazada / Alipay / uni-app internal-library namespaces. The aone-cloud-cli entry directly extends the npm-2026-07-29-ghsa-malware-sweep module's Cluster D (aone-kit, aone-kit-cli, aone-sandbox) - same day, same-scope operator continuing to enumerate Alibaba internal-lib naming.
Cluster E - @zannstore/baileys WhatsApp SDK typosquat (1 package, 17 versions, 2026-07-29)
| Package | Versions | Notes | |---|---|---| | @zannstore/baileys | 2.2.6 - 2.4.4 (17 versions) | attacker-controlled shadow fork of @whiskeysockets/baileys |
Version-range mirrors the legitimate @whiskeysockets/baileys fork tree used by WhatsApp-automation bots, Discord/Telegram bridges, and multi-channel-messaging tooling. Pin-consistent versioning across 17 published versions strongly suggests an attacker maintaining a shadow fork to catch bot developers pulling baileys under an attacker-controlled scope. Same disclosure day as the 07-29 @bowozzz/baileys sibling catalogued in the prior module (probably different operator) - both leverage the popular baileys naming convention for bot ecosystems.
Cluster F - misc single-package RATs, typosquats, and generic-name malware (10 packages, 2026-07-29)
| Package | Version | Notes | |---|---|---| | @omniwatch-wick/cli | all versions | CLI kit impersonation | | @finxsecdemo/utils | 1.0.2 | OpenSSF PA "communicates with malicious domain" trigger - "security demo" scope | | zer0code | 0.2.0 | only exact-versioned entry in the batch - targeted single-version drop | | flight-compare-analyzer | all versions | commercial-travel-tooling impersonation | | test-skill-zip | all versions | Amazon Alexa Skill dev tooling name | | feedback-ai-sdk | all versions | AI-feedback-loop SDK impersonation | | open-worker-cli | all versions | worker-thread CLI impersonation | | data-parser-utils | all versions | generic-name credential stealer | | eslintcmd | all versions | ESLint typosquat, developer-tooling impersonation | | open-worker-cli | all versions | worker-thread CLI impersonation |
High-signal picks: eslintcmd will run at every CI job that references the misnamed dep - pin explicit ESLint versions and grep .eslintrc / package.json scripts. @finxsecdemo/utils was OpenSSF-PA-flagged rather than the generic all-versions boilerplate, suggesting active domain communication observed at analysis time. zer0code@0.2.0 is the only exact-versioned drop in the batch - targeted rather than broad-scatter.
Registry state
All 28 packages security-replaced with 0.0.1-security sentinel tarballs during the 2026-07-29 batch. Original version tarballs are no longer resolvable on the public registry, but private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs BEFORE the takedown WILL keep serving the original versions.
Related tracked activity
- Follows
npm-2026-07-29-ghsa-malware-sweep- that module's "2026-07-29 batch (6 packages)" catalogued only the 6 advisories live at the time it was authored; this module covers the 28 additional 2026-07-29-dated advisories GHSA published later the same UTC day. - Cluster D
aone-cloud-clidirectly extends the 07-28aone-kit/aone-kit-cli/aone-sandboxCluster D operator profile. - Cluster B extends the operator space around
npm-2026-07-17-polymarket-trap-clob-client-mathand the Junepolymarket-clob-math-vercel-loadercluster targeting Polymarket / CLOB trading-bot dependencies. - No
threatActorfield is set - GHSA advisories in this batch use only the CWE-506 boilerplate with no named actor attribution.
Affected packages (28)
- npm@ai-agent-node/agent-node1.0.0
- npm@ai-agent-node/createnode1.0.0
- npm@ai-agent-node/nodesql1.0.0
- npm@ai-plus/de-agent1.0.0
- npm@ai-plus/de-agent-sdk1.0.0
- npm@finxsecdemo/utils1.0.2
- npm@omniwatch-wick/cli1.0.0
- npm@peptide-unit/js-unimode1.0.0
- npm@peptide-unit/peptide-modify1.0.0
- npm@zannstore/baileys2.2.62.2.72.2.82.3.02.3.12.3.22.3.32.3.42.3.52.3.62.3.72.3.92.4.02.4.12.4.22.4.32.4.4
- npmaone-cloud-cli1.0.0
- npmcolder-cli1.0.0
- npmdata-parser-utils1.0.0
- npmdef-open-client1.0.0
- npmeslintcmd1.0.0
- npmfeedback-ai-sdk1.0.0
- npmflight-compare-analyzer1.0.0
- npmlwp-web-client1.0.0
- npmlzd-unified-station-sdk1.0.0
- npmopen-worker-cli1.0.0
- npmpoly-kelly1.0.0
- npmpolymarket-risk-manager1.0.0
- npmstake-math1.0.0
- npmtest-skill-zip1.0.0
- npmts-bn-proto1.0.0
- npmts-precision1.0.0
- npmuniapi-bridge1.0.0
- npmzer0code0.2.0
These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.
Impact
- Any host that installed any of the 28 npm packages listed below should be treated as fully compromised - every GHSA record uses the CWE-506 boilerplate: "any computer that has this package installed or running should be considered fully compromised - rotate all secrets from a different computer" - and no patched version exists
- *Cluster A - `@ai-plus/
+@ai-agent-node/` AI-agent SDK impersonation scopes* (5 packages, all>= 0, all 2026-07-29):@ai-plus/de-agent-sdk,@ai-plus/de-agent,@ai-agent-node/createnode,@ai-agent-node/agent-node,@ai-agent-node/nodesql. Two coordinated attacker-owned scopes publishing under generic AI-agent-tooling names in the same 24h window -de-agent/de-agent-sdkin@ai-plus,createnode/agent-node/nodesqlin@ai-agent-node. Same day, same threat class, same GHSA boilerplate - likely one operator running scope-diverse AI-agent-adjacent malware to catch developers experimenting with agent-SDK integrations - Cluster B - Polymarket / prediction-market tooling impersonator kit (5 packages, all
>= 0, all 2026-07-29):polymarket-risk-manager,poly-kelly,ts-precision,ts-bn-proto,stake-math. Names read as a coordinated set:polymarket-risk-managertargets Polymarket risk / position-sizing;poly-kellytargets Kelly-criterion bet sizing (used in Polymarket trading bots);ts-precisionandts-bn-prototargetbn.js/ big-number arithmetic (Polymarket/CLOB math dependencies);stake-mathtargets staking / DeFi position math. Same-day coordinated publish signature - treat as a single Polymarket-trading-bot targeting operator following the earliernpm-2026-07-17-polymarket-trap-clob-client-mathandinternal-2026-06-*-polymarket-clob-math-vercel-loadercampaigns - *Cluster C - `@peptide-unit/
biotech / chemistry-scope pair** (2 packages, all>= 0, all 2026-07-29):@peptide-unit/peptide-modify,@peptide-unit/js-unimode. Coordinated same-scope publish under domain-specific-sounding biotech names.@peptide-unit/js-unimode` is a nonsense-name pairing under a plausible-looking scope - classic dep-confusion probe against an internal peptide-analysis library namespace at a biotech / pharma target - Cluster D - Alibaba-adjacent Lazada/uni-app/Aone scope (6 packages, all
>= 0, all 2026-07-29):lzd-unified-station-sdk(lzd= Lazada),uniapi-bridge(uni-app SDK),aone-cloud-cli(Alibaba Aone DevOps - extends the 07-28aone-kit/aone-kit-cli/aone-sandboxcluster catalogued innpm-2026-07-29-ghsa-malware-sweep),colder-cli,lwp-web-client,def-open-client. All six flagged all-versions, no patched builds. Consistent with dep-confusion probes against Alibaba / Lazada / Alipay / uni-app internal-library namespaces - Cluster E -
@zannstore/baileysWhatsApp SDK typosquat (17 versions2.2.6→2.4.4):@zannstore/baileys. Version-range mirrors legitimate@whiskeysockets/baileysfork tree (used by WhatsApp automation bots and Discord/Telegram bridges) - pin-consistent versioning strongly suggests an attacker maintaining a shadow fork to catch bot developers pullingbaileysunder an attacker-controlled scope. Same disclosure day as the 07-29@bowozzz/baileyssibling catalogued in the prior module - likely different operators independently targeting the popularbaileysnaming convention - Cluster F - misc single-package RATs, typosquats, and generic-name malware (10 packages, all 2026-07-29):
@omniwatch-wick/cli(all versions - probable coordinated with 07-28xerohub-*and@yancyyu/agentclioperator profile),@finxsecdemo/utils@1.0.2(OpenSSF Package Analysis "communicates with malicious domain" trigger),zer0code@0.2.0(only exact-versioned entry in the batch - targeted single-version drop),flight-compare-analyzer(all versions - commercial-travel-tooling impersonation),test-skill-zip(all versions - Amazon Alexa Skill dev tooling name),feedback-ai-sdk(all versions - AI-feedback-loop SDK impersonation),open-worker-cli(all versions - worker-thread CLI impersonation),data-parser-utils(all versions - generic-name credential stealer),eslintcmd(all versions - ESLint typosquat, developer-tooling impersonation),@finxsecdemo/utils(OpenSSF flag against a "security demo" scope - likely researcher / red-team probe left in the wild) - None of the 28 packages retain original tarballs on the public npm registry - all replaced with
0.0.1-securitysentinel tarballs. Private registry mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs BEFORE the takedown WILL keep serving the original versions
What to do
- 1Grep every lockfile (
package-lock.json,yarn.lock,pnpm-lock.yaml) for each name in the packages map below. Any match is a supply-chain incident: rotate every credential the build runner could reach and re-image the build host - 2Cluster B (Polymarket prediction-market impersonator kit): any hit on
polymarket-risk-manager,poly-kelly,ts-precision,ts-bn-proto, orstake-mathon a host that runs Polymarket / CLOB trading bots or holds market-maker keys: treat as full crypto-wallet-compromise event. Move funds via a clean device BEFORE attempting rotation. Rotate every trading-bot API token, Polymarket / CLOB signing key, and browser-wallet seed accessible from the affected host - 3Cluster A (
@ai-plus/@ai-agent-nodeAI-agent SDK impersonators): any hit on@ai-plus/de-agent-sdk,@ai-plus/de-agent,@ai-agent-node/createnode,@ai-agent-node/agent-node, or@ai-agent-node/nodesql: rotate every LLM API key (OpenAI / Anthropic / Google / Cohere / Mistral / OpenRouter), MCP server credentials, and agent-SDK service tokens accessible from the affected host. Audit LLM provider usage dashboards for unexpected token spend in the exposure window - 4Cluster E (
@zannstore/baileystyposquat): any lockfile hit at any version in the2.2.6→2.4.4range: rotate every WhatsApp Business API token, Meta developer credentials, and any Discord/Telegram bot tokens co-located with the bot install. Audit outbound WhatsApp / Meta API logs for unexpected message traffic during the exposure window - 5*Cluster D (Alibaba-adjacent `lzd-
/uniapi-/aone-cloud-cli`)*: any hit onlzd-unified-station-sdk,uniapi-bridge,aone-cloud-cli,colder-cli,lwp-web-client, ordef-open-client: configure.npmrcscope-to-registry mapping so private-name resolution never falls through to the public registry. Rotate any Alibaba Cloud / Aliyun / Lazada seller-central / uni-app SDK service credentials accessible from the affected host - 6Cluster F single-package hits: any lockfile hit at any listed version is a compromise.
eslintcmdin particular is a linter-tooling typosquat that will run at every CI job - audit.eslintrc/package.jsonscripts for the exact name and pin explicit ESLint versions - 7For projects using
postinstall-scripting packages, runnpm install --ignore-scriptsin CI as defense-in-depth and invoke scripts only for vetted first-party packages - 8Verify none of the 28 listed packages still resolves via your private mirror - internal Artifactory / Nexus / Verdaccio instances routinely cache tarballs and will keep serving the original versions after the public yank
References
- GitHubGitHub Advisory Database - recent npm malware advisoriesgithub.com
- GitHubGHSA-4c3x-2hh8-6pp9 - @ai-plus/de-agent-sdk malware advisorygithub.com
- GitHubGHSA-w62v-8p95-rhf2 - @ai-plus/de-agent malware advisorygithub.com
- GitHubGHSA-79rw-4w2g-9hr5 - @ai-agent-node/createnode malware advisorygithub.com
- GitHubGHSA-h95p-8cf6-7qrc - @ai-agent-node/agent-node malware advisorygithub.com
- GitHubGHSA-fm4j-w897-7h3g - @ai-agent-node/nodesql malware advisorygithub.com
- GitHubGHSA-jcx2-q527-7qcx - polymarket-risk-manager malware advisorygithub.com
- GitHubGHSA-c37j-v3j2-6gf8 - poly-kelly malware advisorygithub.com
- GitHubGHSA-g38h-2r6h-pwr8 - ts-precision malware advisorygithub.com
- GitHubGHSA-wxpc-r4jx-9jrw - ts-bn-proto malware advisorygithub.com
- GitHubGHSA-qcc9-j6wh-4h9h - stake-math malware advisorygithub.com
- GitHubGHSA-mw2h-4g9g-g7vv - @peptide-unit/peptide-modify malware advisorygithub.com
- GitHubGHSA-hghj-5h7q-fq5h - @peptide-unit/js-unimode malware advisorygithub.com
- GitHubGHSA-2rgv-qvc2-5q4h - lzd-unified-station-sdk malware advisorygithub.com
- GitHubGHSA-wpp9-5p7g-7cjh - uniapi-bridge malware advisorygithub.com
- GitHubGHSA-c6xg-mcq6-m594 - aone-cloud-cli malware advisorygithub.com
- GitHubGHSA-x646-p774-9w26 - colder-cli malware advisorygithub.com
- GitHubGHSA-rmm2-5g7m-wj7p - lwp-web-client malware advisorygithub.com
- GitHubGHSA-pxmg-gr7p-wx8p - def-open-client malware advisorygithub.com
- GitHubGHSA-vw26-8qc4-8hmg - @zannstore/baileys malware advisorygithub.com
- GitHubGHSA-x4cm-7r6h-pjg3 - @omniwatch-wick/cli malware advisorygithub.com
- GitHubGHSA-qccg-fq42-3rgc - @finxsecdemo/utils malware advisorygithub.com
- GitHubGHSA-frrq-7m67-mgxg - zer0code malware advisorygithub.com
- GitHubGHSA-wwp4-2j5x-f2m9 - flight-compare-analyzer malware advisorygithub.com
- GitHubGHSA-qw86-6hcg-cj2j - test-skill-zip malware advisorygithub.com
- GitHubGHSA-fh6v-xfxj-m87q - feedback-ai-sdk malware advisorygithub.com
- GitHubGHSA-2p2c-gx9p-5wg8 - open-worker-cli malware advisorygithub.com
- GitHubGHSA-vw6q-xg53-fpxh - data-parser-utils malware advisorygithub.com
- GitHubGHSA-73c6-pgjj-9v82 - eslintcmd malware advisorygithub.com