Feed
CriticalPublished 5 Aug 202642 packages · 42 versions

GitHub Advisory npm CWE-506 sweep - 40+ package 2026-08-05 batch (massive Tinkoff Bank / dolyame BNPL / bnpl-blocks / tramvai / statist enterprise-scope dep-confusion burst, plus `clawtrl-wallet` crypto stealer + `sextant-cli-darwin-arm64` platform-binary + `@lizhao1/memorax-code-internal` + `@cliphijack/santaclaude` Claude-themed clipboard hijack + `llm-interceptor` + `multi-acct` + `kepler`)

Summary

GHSA published 40+ npm CWE-506 advisories dated 2026-08-05 dominated by a massive Tinkoff Bank (Russian bank) enterprise-scope dep-confusion burst: tinkoff-*, dolyame-boxy-* (Tinkoff BNPL), bnpl-blocks-atom-*, tramvai-* (Tinkoff's open-source framework), bigops-*, sme.rko.* internal namespaces. Also clawtrl-wallet (crypto wallet stealer), @cliphijack/santaclaude (Claude-themed clipboard hijack), sextant-cli-darwin-arm64, @lizhao1/memorax-code-internal, llm-interceptor, multi-acct, kepler, express-dever, svelte-mapped-metrics, streak-math-calc, streak-calc-metrics, svelte-mapping-core, eslint-plugin-vitest-ts, tailwindcss-scrollbar-hide, express-rate-controller, @stageflight-testbed/a, @workoscalif/sudoku, trapp-check-logs, sme-foundation-frame-manager.

dependency-confusionci-cd-compromisecredential-theftcrypto-wallet-drainobfuscation
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · npm Security
Also known as
2026-08-05 GHSA npm batch · Tinkoff Bank dep-confusion burst · Dolyame BNPL squat cluster · bnpl-blocks-atom cluster
Ecosystems
npm
Packages tracked
42

What happened

On 2026-08-05, the GitHub Advisory Database published 40+ new npm CWE-506 (Embedded Malicious Code) advisories dominated by a massive coordinated dep-confusion probe against Tinkoff Bank (JSC Tinkoff, one of Russia's largest banks) and its adjacent BNPL / SME / open-source-framework namespaces.

Cluster A - Tinkoff Bank / dolyame BNPL / bnpl-blocks internal-namespace dep-confusion burst (25+ packages, 2026-08-05)

A precise dep-confusion probe against Tinkoff Bank internal engineering namespaces:

Sub-cluster A.1 - Dolyame BNPL (Tinkoff's "buy-now-pay-later" product)

| Package | Notes | |---|---| | dolyame-boxy-independent-bnpl-items | BNPL items component | | dolyame-boxy-independent-bnpl-info-slider | BNPL info slider | | dolyame-boxy-independent-bnpl-partners | BNPL partners list | | dolyame-boxy-independent-bnpl-search | BNPL search | | dolyame-boxy-independent-bnpl-picture-gallery | BNPL image gallery | | dolyame-boxy-fonts | Fonts bundle | | dolyame-boxy-desktop-bnpl-text-block | BNPL text block |

Sub-cluster A.2 - BNPL blocks atoms

| Package | Notes | |---|---| | bnpl-blocks-atom-bnpl-email-form | Email form | | bnpl-blocks-atom-bnpl-badge | Badge atom | | bnpl-blocks-atom-bnpl-dropdown | Dropdown atom | | bnpl-blocks-atom-bnpl-info-card | Info card atom | | bnpl-blocks-atom-bnpl-news-card | News card atom | | bnpl-blocks-atom-bnpl-integrations-breadcrumbs | Breadcrumbs | | bnpl-blocks-atom-bnpl-dolyame-button | Dolyame CTA button | | bnpl-blocks-atom-bnpl-action-card | Action card |

Sub-cluster A.3 - Tinkoff internal statist / SME / RKO client libraries

| Package | Notes | |---|---| | tinkoff-statist-browser-typed-client-itsa.candy.selfservicesupport.frontend.events | Statist browser event client | | tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events | SME RKO mobile-pay event client | | tinkoff-pfp-block-desktop-tabs | PFP block tabs | | tinkoff-volna-zustate | Volna zustate | | tramvai-module-feature-toggle | Tramvai (Tinkoff's open-source React framework) feature-toggle module | | sme-foundation-frame-manager | SME foundation | | bigops-auth | BigOps auth |

Sub-cluster A.4 - Test / probe / other Tinkoff-adjacent

| Package | Notes | |---|---| | vvvedernikov-test-another-test | Developer-named test probe | | trapp-check-logs | Trapp check logs | | @ikbal_fadilah_vanexa01/vanexa-agent | Vanexa agent variant | | @stageflight-testbed/a | Stageflight testbed |

The Cyrillic-transliteration name conventions (dolyame = Dolyame BNPL, sme.rko = SME / RKO cash management, volna = wave, tramvai = tram, vvvedernikov = a Russian surname pattern) plus the depth and breadth of internal-namespace coverage confirm this is a targeted operation against Tinkoff Bank's internal npm registry. The operator has clearly enumerated real Tinkoff internal package names from a leaked package manifest, an accidentally-public repo, or a scraped package.json from an internal Tinkoff project.

Any Tinkoff Bank developer with a misconfigured .npmrc scope precedence who ran npm install in the 2026-08-05 window could have resolved the malicious public versions instead of the internal legitimate ones. Given the specificity of the internal namespaces, the yield rate is likely high on any Tinkoff developer laptop or CI runner that hit the public registry for these names.

Cluster B - clawtrl-wallet crypto-wallet stealer (1 package, 2026-08-05)

| Package | Notes | |---|---| | clawtrl-wallet | Explicit crypto-wallet-drain naming |

Cluster C - @cliphijack/santaclaude Claude-themed clipboard hijack (1 package, 2026-08-05)

| Package | Notes | |---|---| | @cliphijack/santaclaude | Scope name telegraphs clipboard-hijack payload; Claude-themed package name for developer targeting |

Scope @cliphijack is an unusually direct payload-class signal - clipboard hijacking. Package name santaclaude is a Claude-themed mock/target aimed at developers searching for Claude Code utilities. Clipboard-hijack payloads typically monitor pbcopy/xclip/xsel output or hook browser clipboard events and replace cryptocurrency addresses with attacker-controlled addresses at paste time - so a developer copy-pasting a Bitcoin/Ethereum/Solana address to send funds ends up sending to the attacker's wallet instead. Any recent crypto transaction on a compromised host should be verified against the intended destination address.

Cluster D - Platform-binary + internal-code cluster (2 packages, 2026-08-05)

| Package | Notes | |---|---| | sextant-cli-darwin-arm64 | Apple Silicon platform-binary squat for a sextant-cli target | | @lizhao1/memorax-code-internal | Internal-code shape suggests dep-confusion probe against memorax org |

Cluster E - LLM / agent tooling (2 packages, 2026-08-05)

| Package | Notes | |---|---| | llm-interceptor | Generic LLM interceptor tool naming | | multi-acct | Multi-account tooling naming |

Cluster F - Framework / build-tool typosquats and misc long tail (2026-08-05)

svelte-mapped-metrics, streak-math-calc, streak-calc-metrics, svelte-mapping-core, eslint-plugin-vitest-ts, tailwindcss-scrollbar-hide, express-dever, express-rate-controller, kepler, @workoscalif/sudoku. Standard CWE-506 fully-compromised remediation applies.

Registry state

All packages yanked / security-replaced from npm during the 2026-08-05 takedown. Private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs BEFORE the takedown WILL keep serving the original versions.

Related tracked activity

  • Tinkoff / dolyame / BNPL cluster continues into 2026-08-06 (see npm-2026-08-06-ghsa-malware-sweep Cluster H sub-list) - the operator is running a multi-day enterprise-namespace enumeration burst against Tinkoff.
  • @cliphijack/santaclaude matches the pattern of prior clipboard-hijack cryptocurrency-address-swap tools catalogued across recent months.
  • No threatActor field set - GHSA advisories use OpenSSF MAL-2026-* identifiers only. The consistency and volume of the Tinkoff cluster is strong evidence of a single operator running a scripted enumeration campaign.

Affected packages (42)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • Cluster A - Tinkoff Bank / dolyame BNPL / bnpl-blocks internal-namespace dep-confusion burst (25+ packages, 2026-08-05): a coordinated dep-confusion probe against Tinkoff Bank (JSC Tinkoff Bank, one of Russia's largest banks) internal package namespaces. Squats include: dolyame-boxy-* (Dolyame is Tinkoff's BNPL "buy-now-pay-later" product), bnpl-blocks-atom-bnpl-* (BNPL React component atoms), tinkoff-statist-browser-typed-client-sme.rko.* (Tinkoff SME / RKO internal client libraries - RKO = Расчётно-Кассовое Обслуживание, cash-management for business accounts), tramvai-module-feature-toggle (Tramvai is Tinkoff's open-source React framework), sme-foundation-frame-manager, bigops-*. Any Tinkoff Bank developer whose local .npmrc or CI misconfigured the private registry preference could pull the malicious public versions
  • Cluster B - clawtrl-wallet crypto-wallet stealer (1 package, 2026-08-05): explicit crypto-wallet-drain naming. Standard CWE-506 boilerplate applies but the name and single-version drop matches the profile of a targeted wallet-stealer package. Any host that installed should treat every crypto wallet on it as fully compromised
  • Cluster C - @cliphijack/santaclaude Claude-themed clipboard hijack (1 package, 2026-08-05): scope @cliphijack telegraphs the payload class - clipboard hijacking. The santaclaude package name mocks Claude Code / Anthropic tooling, targeting developers searching for Claude-adjacent utilities. Clipboard hijack payloads typically replace cryptocurrency addresses copied to the clipboard with attacker-controlled addresses at paste time
  • Cluster D - Platform-binary + internal-code cluster (2 packages, 2026-08-05): sextant-cli-darwin-arm64 (Apple Silicon platform binary squat), @lizhao1/memorax-code-internal (internal-code package name shape suggests dep-confusion probe against a memorax org)
  • Cluster E - LLM / agent tooling (2 packages, 2026-08-05): llm-interceptor, multi-acct - naming targets developers building LLM/AI tooling
  • Cluster F - Framework / build-tool typosquats (5+ packages, 2026-08-05): svelte-mapped-metrics, streak-math-calc, streak-calc-metrics, svelte-mapping-core, eslint-plugin-vitest-ts, tailwindcss-scrollbar-hide, express-dever, express-rate-controller, vvvedernikov-test-another-test, trapp-check-logs, kepler, @ikbal_fadilah_vanexa01/vanexa-agent, @stageflight-testbed/a, @workoscalif/sudoku. Standard CWE-506 fully-compromised remediation applies
  • All packages yanked / security-replaced from npm during the 2026-08-05 takedown. Private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs BEFORE the takedown WILL keep serving the original versions

What to do

  1. 1Grep every lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml) for the full 2026-08-05 package list below - especially the Tinkoff / dolyame / bnpl-blocks / tramvai / sme.rko cluster
  2. 2For Tinkoff Bank / Tinkoff ecosystem developers: this is a targeted enterprise-scope dep-confusion probe against your internal package namespaces. Audit .npmrc and .yarnrc files across all developer laptops and CI runners to confirm the private Tinkoff registry is set as the primary source with always-auth=true. Configure explicit @dolyame:registry, @tinkoff:registry, and @sme.rko:registry mappings if any exist. Add explicit overrides blocks in package.json for the specific package names above
  3. 3For clawtrl-wallet matches: treat as a crypto-wallet stealer incident - move every crypto wallet balance to a fresh seed on an isolated host, rotate all seed phrases
  4. 4For @cliphijack/santaclaude matches: check clipboard-related utilities that may have been auto-installed. Any recent cryptocurrency transaction where you copy-pasted the destination address should be verified against the intended address - clipboard-hijack payloads specifically swap crypto addresses at paste time
  5. 5For sextant-cli-darwin-arm64 matches: platform-binary distribution packages usually resolve via optionalDependencies + platform detection. Verify which real sextant-cli package your build was trying to install; the operator is squatting the Apple Silicon variant
  6. 6For all npm installs in CI, run with --ignore-scripts as defense-in-depth to prevent preinstall/postinstall payloads from executing
  7. 7Verify none of the 2026-08-05 packages still resolves via your private mirror

References

npm-2026-08-05-ghsa-malware-sweep