Feed
CriticalPublished 12 Aug 2026159 packages · 184 versions

GitHub Advisory npm CWE-506 sweep - 2026-08-12 batch (Web3 typosquat webhook.site ring day-2 `permit2`+`camelot-ammv2-*`+`boring-vault`+`augustdigital-sdk`+`upshift-*`, Ethereum-RPC-C2 `envpack-conf`+`tailwind-form-templates` XOR-encrypted second-stage on blockchain, `svelte-kit-vim`+`kit-map-vim` map-streak-kit day-4 continuation, `sui-gql`+`bcs-compact` Sui `@mysten/*` typosquat continuation, ~50-package `@years17/18/19/20/*` n8n-nodes-utils-helper red-team SSH-backdoor mass drop, `internallib_v756`/`v392` bare `/dev/tcp/10.0.74.63/4444` reverse shell, `mcp-util-helpers` webhook.site R-shell channel, `passkeys-react` Burp Collaborator OAST recon, `bb-twl-k7x2` Twilio-internal dep-confusion, `@telekom-ods/react-ui-kit` Deutsche Telekom internal-scope, `verify-cli`+`@assetshop/verify-cli` OAST recon pair, `dakumangalsingh` Java-Robot RAT with jpackage wrapper, boilerplate CWE-506 mass npm flood ~100 packages)

Summary

~160 npm CWE-506 advisories published 2026-08-12. Headline: Web3 typosquat webhook.site ring day-2 (permit2, camelot-ammv2-core/periphery, boring-vault, augustdigital-sdk, upshift-finance/config) with identical env/wallet-keystore exfil TTP as the 08-11 OpenZeppelin/Aerodrome ring; Ethereum-RPC-C2 pair (envpack-conf, tailwind-form-templates) fetching XOR-encrypted second-stage from blockchain via wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a; and a *~50-package `@years17/18/19/20/` red-team n8n mass drop** installing pwn@kali SSH backdoors.

typosquatcredential-theftcrypto-wallet-draindependency-confusionobfuscationinfostealermaintainer-takeover
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · npm Security · amazon-inspector · kam193 bad-packages
Also known as
2026-08-12 GHSA npm batch · Web3 webhook.site typosquat ring day-2 · Ethereum-RPC-C2 register · map-streak-kit family day-4 · years17-20 n8n red-team mass drop · mssjeep843 Web3 cluster
Ecosystems
npm
Packages tracked
159

What happened

On 2026-08-12, the GitHub Advisory Database published ~160 new npm CWE-506 (Embedded Malicious Code) advisories - the largest single-day batch in the sweep-tracking window since the 2026-05-11 TanStack Mini Shai-Hulud burst. The shape is a mix of high-conviction targeted operations (Web3 typosquat continuations, Deutsche Telekom compromise, Twilio dep-confusion probe, n8n red-team mass drop) and a very large boilerplate CWE-506 flood.

Cluster A - Web3 typosquat webhook.site credential-theft ring day-2 (7 packages, same-operator continuation of 2026-08-11 Cluster A)

| Package | Versions | GHSA | Impersonated target | |---|---|---|---| | permit2 | 1.0.0, 1.0.1 | GHSA-5hx7-m92r-hc5c | Uniswap Permit2 SDK (@uniswap/permit2-sdk) | | camelot-ammv2-core | 1.0.0, 1.1.0, 1.1.1 | GHSA-j6vj-qx8g-mv2c | Camelot DEX AMM v2 core contracts | | camelot-ammv2-periphery | 1.0.0, 1.1.0, 1.1.1 | GHSA-m3cv-6763-2mrv | Camelot DEX AMM v2 periphery | | boring-vault | 1.0.0, 1.1.0, 1.1.1 | GHSA-2hm3-fxxw-fwgw | Veda BoringVault Solidity framework | | augustdigital-sdk | 8.20.1 | GHSA-pfx4-g5xh-hpf6 | @augustdigital/sdk | | upshift-finance | 1.0.0 | GHSA-p98f-6986-rf79 | August Digital / Upshift Finance | | upshift-config | <=0.5.14 | GHSA-75gq-p797-7w4c | August Digital / Upshift config |

Sub-ring A1 - permit2 ships the identical webhook.site payload as the 08-11 OpenZeppelin/Aerodrome/Euler ring: preinstall + postinstall both trigger, env-var filter for KEY/TOKEN/SECRET/PRIVATE/MNEMONIC/AWS/WALLET, reads ~/.aws/, ~/.ssh/, ~/.kube/, ~/.docker/, ~/.netrc, ~/.npmrc, blockchain keystores under Solana / Sui / Foundry / Anchor, detached child process with randomised delay + sandbox-evasion hostname checks, POST to hardcoded webhook.site endpoint. Same operator or coordinated with the 08-11 ring.

Sub-ring A2 - mssjeep843 npm account (published camelot-ammv2-core, camelot-ammv2-periphery, boring-vault plus two related PyPI packages the 08-11 PyPI sweep picked up): v1.0.0 does env-var + wallet-keystore + .npmrc/.gitconfig exfil to a shared webhook, v1.1.0 escalates to reading full file contents up to 4000 bytes from .aws/credentials, .ssh/id_rsa/id_ed25519, and Solana/Anchor/NEAR/Sui wallet keystores plus regex-scans local .env files for BEARER, API, INFURA, ALCHEMY, PRIVATE_KEY patterns.

Sub-ring A3 - awugochogabriel@gmail.com freemail account (published augustdigital-sdk, upshift-finance, upshift-config within seconds of each other on 2026-08-10, disclosed 08-12): brand-hijack repack of @augustdigital/sdk with a hidden postinstall that beacons to build-metrics-collector.cdn-ops-health.workers.dev/npm-install/ disguised as CDN health metrics. Payload transmits hostname, username, cwd, package details, and ISO timestamp - no secondary credential-harvest identified. The Cloudflare Workers cover makes the exfil traffic look like ordinary CDN telemetry.

All three sub-rings targeting DeFi / Solidity SDKs on the same day continue the sustained typosquat pressure against DeFi vendor namespaces documented in the 08-11 sweep. Expect further sibling drops in the next 24-72h.

Cluster B - Ethereum-RPC-C2 pair with XOR-encrypted second-stage on blockchain (2 packages)

| Package | Versions | GHSA | Impersonated target | Wallet address | |---|---|---|---|---| | envpack-conf | 1.0.1 | GHSA-fw27-f4gv-qw69 | Sindre Sorhus pkg-conf | 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a | | tailwind-form-templates | <=0.7.4 | GHSA-f88v-2vrh-8v5c | @tailwindcss/forms | 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a |

Both packages query public Ethereum RPC endpoints and blockchain explorers at import time to retrieve attacker-controlled instructions from transactions the operator sent from wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a. The transaction data decodes to two IPv4 addresses; the malware then fetches an XOR-encrypted second-stage payload from <IP>/0x/cls with custom headers, decrypts it, and executes it via eval() + spawned Node child processes. Strings are Unicode-escaped (\uXXXX) throughout.

The operator can rotate the second-stage IPs silently by publishing new transactions without republishing the package - taking down the two currently-staged IPs does not neutralise the loader. envpack-conf typosquats Sindre Sorhus's pkg-conf (byline "Sinde Sorus" - one letter off in first and last name); tailwind-form-templates shadows @tailwindcss/forms. Same wallet address across both packages - one operator staging both.

Cluster C - svelte-kit-vim + kit-map-vim map-streak-kit family day-4 continuation (2 packages)

| Package | Versions | GHSA | |---|---|---| | svelte-kit-vim | 1.0.0 | GHSA-mpgw-38v3-8q5v | | kit-map-vim | 1.0.0 | GHSA-hg96-r46x-6f4w |

Boilerplate CWE-506 on both. Fourth consecutive daily drop - the register is now <framework>-kit-<editor> and kit-map-<editor>, permuting the 08-11 register (<framework>-<editor>-kit, kit-<editor>-map) which itself permuted the 08-10 register (<framework>-kit-<streak>, kit-<map>-<streak>) and the 08-08 base (map-streak-kit, streak-map-kit, svelte-streak-kit, svelte-kit-cache). Treat as sibling drops of the 08-08 Linux implant + systemd persistence + SSH-key exfil family until Socket/OpenSSF post differentiated samples.

Cluster D - sui-gql + bcs-compact Sui blockchain typosquat continuation (2 packages)

| Package | Versions | GHSA | Typosquats | |---|---|---|---| | sui-gql | >=0 | GHSA-4958-mj82-77pj | @mysten/sui/graphql/client | | bcs-compact | >=0 | GHSA-xr26-x39h-746w | @mysten/bcs |

Boilerplate CWE-506 - short-form variant of the 08-11 sui-gql-client/sui-bcs-codec pair. Same-operator second-day drop staging both long-form and short-form names for each Sui module.

Cluster E - @years17/* + @years18/* + @years19/* + @years20/* n8n-nodes-utils-helper red-team mass drop (~50 packages)

Approximately 50 packages across four scopes (@years17, @years18, @years19, @years20) with suffixes -a through -y plus -helper-utils. This is a single-operator red-team mass drop targeting n8n community node maintainers - all share the same exfil endpoint (https://jasabersama.id/portfolio-data.php) and the same triple-execution model:

  1. Postinstall writes /tmp/pwned.txt and executes reconnaissance (id, hostname, git --version, node --version, n8n install-path checks, ~/.n8n/ directory contents).
  2. Module-load-time payload runs the same recon and writes /tmp/n8n_pwned.txt - the advisory comment on @years17/n8n-nodes-helper-utils explicitly notes execution happens "inside n8n's main process with no sandbox".
  3. Workflow execute() on the exported node class runs id, hostname, uname -a, and directory listings, returning results marked pwned: true.

Specific samples widen the impact:

  • @years17/n8n-nodes-utils-helper-e appends the attacker SSH key labeled pwn@kali to /home/ubuntu/.ssh/authorized_keys, runs sudo -n -l to enumerate passwordless sudo capability, checks docker ps, and registers a PwnNode class inside n8n that runs additional commands and returns pwned: true.
  • @years20/n8n-nodes-utils-helper-h base64-encodes recon output and beacons to jasabersama.id/portfolio-data.php with TLS validation disabled; URL parameters include a shell pipeline suggesting command-and-control tasking.

The scale (~50 packages) and the identical infrastructure make this a coordinated red-team engagement (or a red-team-tool-based attacker campaign) against organisations using n8n community nodes at scale. The pwn@kali SSH key label plus /tmp/pwned.txt//tmp/n8n_pwned.txt markers plus PwnNode class name are consistent with a Kali-hosted red-team engagement.

Cluster F - internallib_v756 + internallib_v392 bare /dev/tcp/10.0.74.63/4444 reverse-shell dep-confusion (2 packages, sibling of 08-11 internallib_v164)

| Package | Versions | GHSA | C2 | |---|---|---|---| | internallib_v756 | <=1.0.7 | GHSA-49mj-627r-8grx (+ GHSA-933g-5588-v5hp) | 10.0.74.63:4444 via /dev/tcp | | internallib_v392 | >=0 | GHSA-j9qq-rx28-vcjh | boilerplate (sibling) |

internallib_v756 executes at module-load-time via execSync an interactive bash shell to hardcoded RFC1918 address 10.0.74.63:4444 via /dev/tcp - fires with no conditional logic on every require. internallib_v392 is the boilerplate sibling. Same operator as the 08-11 internallib_v164 - naming register internallib_v<3-digit random> continues.

Cluster G - mcp-util-helpers webhook.site R-shell channel (1 package)

| Package | Versions | GHSA | C2 channel | |---|---|---|---| | mcp-util-helpers | 1.0.0 | GHSA-76x8-h996-qvxr | webhook.site (bidirectional) |

Preinstall runs scripts/check-env.js: collects whoami/id/uname + ip route / ss -tlnp / netstat / running processes / Docker containers + credential env vars + ~/.ssh/ contents + /etc/passwd//etc/hosts, POSTs to webhook.site, then parses the response body for cmd or url fields and executes attacker-supplied shell commands or downloads and runs payloads to /tmp/.mcp-util-setup - a full command-and-control channel over the webhook response body. Naming targets the Model Context Protocol (MCP) tooling ecosystem.

Cluster H - passkeys-react Burp Collaborator OAST recon (1 package)

| Package | Versions | GHSA | Beacon | |---|---|---|---| | passkeys-react | 1.0.1 | GHSA-8rr9-mc57-cwmx | ltivq9rn7t7gkxho4o1micsk6bc20uoj.oastify.com |

Preinstall collects hostname, username, homedir, DNS servers, cwd, /etc/passwd, /etc/hosts; HTTPS-GETs to a Burp Collaborator subdomain. Naming targets the WebAuthn / passkey React ecosystem.

Cluster I - bb-twl-k7x2 Twilio-internal dep-confusion (1 package)

| Package | Versions | GHSA | Beacon | |---|---|---|---| | bb-twl-k7x2 | 1.0.0, 1.0.1 | GHSA-3ffh-ppq4-pgrx | http://whstool.brkd.no/cb53e6db-e043-4383-89e9-853c9088ee5d/ |

canary.js runs at install: os.hostname(), id, hostname -I, ip addr, ls /, ls -a $HOME, and getent hosts internal.twilio.com to probe internal-DNS resolvability. Searches for _auth/_authToken/password tokens in .npmrc across HOME/root/etc/parent, hits AWS instance metadata for IAM role info, exfils via HTTP GET query string over unencrypted HTTP. If your build host resolves internal.twilio.com and pulled this package, the operator now knows.

Cluster J - @telekom-ods/react-ui-kit Deutsche Telekom internal-scope compromise (1 package, 2 versions, /etc/shadow attempt)

| Package | Versions | GHSA | Beacon | |---|---|---|---| | @telekom-ods/react-ui-kit | 2.6.0, 2.6.9 | GHSA-7hwp-8qhg-wfmp | d9t83osijf9n1gb62e4gxfioysijywqww.oast.me |

Installation-hook shell command reads /etc/passwd, /etc/hosts, and conditionally /etc/shadow, embeds username+hostname in the callback URL, HTTPS-GETs to an oast.me subdomain. Publisher metadata matched legitimate prior releases - the advisory notes compromised maintainer account or supply-chain injection, not typosquat. @telekom-ods is a Deutsche Telekom Open Digital Solutions internal scope.

Cluster K - verify-cli + @assetshop/verify-cli dep-confusion recon pair (2 packages)

| Package | Versions | GHSA | Beacon | |---|---|---|---| | verify-cli | 99.0.0 | GHSA-3xrr-9gq8-rv8h | 5f8a1ed70fb7761d678agw9bucryyyyyb.oast.site | | @assetshop/verify-cli | 99.0.0, 99.0.1 | GHSA-9vm3-xhgh-q4pr | 5f8a1ed70fb7761d678agw9bapayyyyyb.oast.site |

verify-cli preinstall base64-encodes /etc/passwd, /etc/hosts, /etc/shadow + whoami/hostname/id, POSTs to OAST. @assetshop/verify-cli collects host metadata, HTTPS-GETs to OAST, and fires a DNS-fanout stub ${user}.${hostname}.assetshop-verify-cli.<oast-host>.

Cluster L - dakumangalsingh Java-Robot Windows RAT with jpackage wrapper (1 package, 3 versions)

| Package | Versions | GHSA | Payload | |---|---|---|---| | dakumangalsingh | 1.0.0, 1.0.1, 1.1.0 | GHSA-h2fc-hhv7-4596 | DakuMangalSingh.exe (jpackage) + virus.jar |

Postinstall auto-executes on Windows. virus.jar bundles Java-Robot screen capture, keystroke/mouse-input synthesis, host fingerprinting, HKCU+startup-shortcut persistence, and an anti-forensics cleanup batch. Same-operator sibling of the boilerplate dakumangalsingh_virus from 08-11 Cluster I.

Cluster M - Massive random-name / themed-name npm flood (~100+ boilerplate packages)

A single-day burst of ~100 packages with random-looking or thematically-clustered names. Random group: hgdvfuflnb, jkbnwsdf8, cvbniydplwe3, cvbmxiowkwqla6, csbcldfvivwfgd4, bmgki3g6fh3, and many more. Themed group: aviation (china_airlines), Taiwan (ms_aidc_com_tw), telecom (unitel3/unitel4, mobicommn, mobicwkgjmx), Chinese-name lures (yangming708/yangming8, kanyut, thundertiger, prezdentkxheiw), passport/ID lures (passport811, egypt0811, airdzticket). All carry boilerplate CWE-506 without differentiated behavioural analysis. Naming pattern suggests coordinated multi-target dep-confusion probes plus mass automated npm spam. Blast radius uncharacterised - treat as capable of the same credential-theft behaviour as the fully-analysed batch members.

Cluster N - @noxzacode/* + noxleys operator cluster (3 packages)

| Package | Versions | GHSA | |---|---|---| | @noxzacode/eslint-config | >=0 | GHSA-7x8x-h24p-92f4 | | @noxzacode/libsignal-node | >=0 | GHSA-7p3j-35rp-g3v5 | | noxleys | >=0 | GHSA-rch8-8p8v-23j7 |

Same-day publication implies one operator. libsignal-node is a Signal Protocol library typosquat; eslint-config is generic. Boilerplate CWE-506.

Cluster O - @bikli/* + bikli* operator cluster (5 packages)

| Package | Versions | GHSA | |---|---|---| | @bikli/bikli | >=0 | GHSA-jrmr-j9fg-c874 | | @bikli/cli | >=0 | GHSA-cc5p-hf7h-rrjh | | biklirouter | >=0 | GHSA-f5c6-4rpr-wjhp | | bikliwrapper | >=0 | GHSA-3qxv-77j4-mg7c | | biklimaster | >=0 | GHSA-pcfp-4v4q-w735 |

Single operator staging both scoped (@bikli/*) and unscoped (bikli*) forms same-day. Boilerplate CWE-506.

Registry state

All ~160 packages yanked or security-holding-replaced from npm during the 2026-08-12 takedown window. Private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs before takedown will keep serving the malicious versions.

Related tracked activity

  • Web3 typosquat webhook.site register continuation: Cluster A is the second-day drop of the 08-11 Cluster A OpenZeppelin/Aerodrome/Euler ring. Same operator, targeting expands to Uniswap Permit2, Camelot AMM v2, Veda BoringVault, August Digital, Upshift Finance. Predicted 08-13/14/15 continuations targeting Compound, Aave, Morpho, Yearn, or Curve.
  • Ethereum-RPC-C2 register: Cluster B is a new register using public Ethereum RPCs as a C2 rendezvous point via a hardcoded wallet address (0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a). If further packages appear that fetch instructions from this wallet, they belong here.
  • map-streak-kit Linux implant family day-4: Cluster C is the fourth consecutive daily drop of the family established on 2026-08-08 and continued 08-10 and 08-11.
  • internallib_v<random> register: Cluster F continues 08-11 internallib_v164. The 10.0.74.63:4444 RFC1918 C2 host implies a specific-network target rather than a broad campaign.
  • *Sui `@mysten/ typosquat register**: Cluster D continues [08-11 sui-gql-client/sui-bcs-codec`](/incident/npm-2026-08-11-ghsa-malware-sweep).
  • Deutsche Telekom compromise (Cluster J): not previously seen in tracked data. Escalate at DT if you can - the advisory suggests maintainer-account or CI/CD compromise, not typosquat.
  • Discovery credits: OpenSSF malicious-packages, OpenSSF Package Analysis, npm Security, amazon-inspector, kam193 bad-packages. No named threat actor.

Affected packages (159)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • Cluster A - Web3 typosquat webhook.site credential-theft ring day-2 (6+ packages, same operator as 08-11): permit2@1.0.0..1.0.1 (Uniswap Permit2 SDK typosquat) ships the identical postinstall payload as the 08-11 OpenZeppelin/Aerodrome/Euler ring - env-var filter for KEY/TOKEN/SECRET/PRIVATE/MNEMONIC/AWS, reads ~/.aws/, ~/.ssh/, ~/.kube/, ~/.docker/, blockchain keystores (Foundry, Solana, Sui, Anchor), detached-process delay + sandbox evasion, POST to hardcoded webhook.site endpoint. camelot-ammv2-core@1.0.0..1.1.1 and camelot-ammv2-periphery@1.0.0..1.1.1 (Camelot DEX AMM v2 typosquat pair, published by npm account mssjeep843) escalate in v1.1.0 to reading full file contents up to 4000 bytes from .aws/credentials, .ssh/id_rsa, .ssh/id_ed25519, and Solana/Anchor/NEAR/Sui wallet keystores. boring-vault@1.0.0..1.1.1 (Veda BoringVault framework typosquat, same mssjeep843 account) shares infrastructure with the camelot pair. augustdigital-sdk@8.20.1, upshift-finance@1.0.0, and upshift-config@<=0.5.14 (brand-hijack of @augustdigital/sdk, freemail account awugochogabriel@gmail.com) beacon to build-metrics-collector.cdn-ops-health.workers.dev/npm-install/ disguised as CDN health metrics. Both sub-rings are the same-operator (or coordinated) continuation of the 08-11 Web3 typosquat wave
  • Cluster B - Ethereum-RPC-C2 pair with XOR-encrypted second-stage on blockchain: envpack-conf@1.0.1 (Sindre Sorhus pkg-conf typosquat, byline "Sinde Sorus") and tailwind-form-templates@<=0.7.4 (@tailwindcss/forms typosquat) both query public Ethereum RPC endpoints and blockchain explorers to retrieve attacker-controlled instructions embedded in transactions from a hardcoded wallet (0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a). The transaction data decodes to two IPv4 addresses; the malware then fetches an XOR-encrypted second-stage payload from those hosts via /0x/cls, decrypts it, and executes it via eval() + spawned Node child processes. Strings are Unicode-escaped (\uXXXX) to defeat static scanning. Because the C2 rendezvous point is a blockchain wallet the operator can rotate the payload silently by publishing a new transaction - taking down the two staged IPs does not neutralise the loader
  • Cluster C - svelte-kit-vim + kit-map-vim map-streak-kit family day-4 continuation: svelte-kit-vim@1.0.0 and kit-map-vim@1.0.0 carry only boilerplate CWE-506 on their GHSA pages, but the naming morphology is a permutation of the 08-11 batch's svelte-vim-kit/kit-vim-map which itself continued the 08-10 svelte-kit-streak/kit-map-streak and the 08-08 map-streak-kit family original. Fourth consecutive daily drop from this operator - treat as capable of the same Linux implant + systemd persistence + SSH-key + credential exfil the 08-08 sample established until Socket or OpenSSF post a differentiated sample
  • Cluster D - sui-gql + bcs-compact Sui blockchain typosquat pair continuation: sui-gql@>=0 and bcs-compact@>=0 (boilerplate CWE-506) continue the 08-11 sui-gql-client/sui-bcs-codec Sui @mysten/* typosquat register. Second-day drop from what appears to be the same operator staging both a long-form (-client, -codec) and short-form (bare) name for each Sui module. Treat as capable of the same wallet-key theft / credential-exfil behaviour as Cluster A until Socket or OpenSSF post the malicious-package sample
  • *Cluster E - `@years17/ + @years18/ + @years19/ + @years20/ n8n-nodes-utils-helper red-team mass drop (~50 packages, SSH backdoor + jasabersama.id` exfil): @years17/n8n-nodes-utils-helper-a..z, @years18/n8n-nodes-utils-helper-a..z, @years19/n8n-nodes-utils-helper-a..z, @years20/n8n-nodes-utils-helper-a..z, @years17/n8n-nodes-helper-utils (approximately 50 packages across four scopes) form a single-operator red-team mass drop targeting n8n community node maintainers. The @years17/n8n-nodes-helper-utils sample runs postinstall that writes /tmp/pwned.txt, executes at module-load-time writing /tmp/n8n_pwned.txt (advisory comment: "inside n8n's main process with no sandbox"), and exports a HelperUtils n8n node whose execute() runs diagnostic commands and returns pwned: true. The @years20/n8n-nodes-utils-helper-h sample base64-encodes recon output and beacons to https://jasabersama.id/portfolio-data.php with TLS validation disabled. The @years17/n8n-nodes-utils-helper-e sample appends the attacker's SSH key labeled pwn@kali to /home/ubuntu/.ssh/authorized_keys, runs sudo -n -l to enumerate passwordless-sudo capability, and enumerates Docker containers. Any n8n installation that pulled any `@years17/18/19/20/ package must be treated as having a persistent SSH backdoor installed for the pwn@kali operator plus a PwnNode` capable of running arbitrary commands inside every workflow execution
  • Cluster F - internallib_v756 + internallib_v392 bare reverse-shell dep-confusion lures (/dev/tcp/10.0.74.63/4444): internallib_v756@<=1.0.7 executes at module-load time via execSync an interactive bash shell to hardcoded RFC1918 address 10.0.74.63:4444 via /dev/tcp - fires with no conditional logic on every require. internallib_v392@>=0 is the boilerplate sibling. Both are the internal-scope internallib_v<random> continuation of internallib_v164 from 2026-08-11 - same operator running a mass dep-confusion probe against any org whose internal scope contains a package named internallib. The 10.0.74.63:4444 address is an RFC1918 host - the operator is running the listener inside an internal network they already have a foothold in, so the exfil only succeeds when the victim host can route to that subnet (implying the target is a specific internal deployment, not a broad campaign)
  • Cluster G - mcp-util-helpers webhook.site R-shell (MCP tooling typosquat): mcp-util-helpers@1.0.0 runs scripts/check-env.js from preinstall - collects whoami/id/uname + network config (ip route, ss -tlnp) + running processes + Docker containers + credential env vars + ~/.ssh/ contents + /etc/passwd//etc/hosts, POSTs to a hardcoded webhook.site endpoint, then parses the response for cmd or url fields and executes arbitrary shell commands or downloads and runs payloads to /tmp/.mcp-util-setup - a full command-and-control channel over the webhook.site response body. Naming targets the Model Context Protocol tooling ecosystem (MCP servers, Claude Code MCP, etc)
  • Cluster H - passkeys-react Burp Collaborator OAST recon (passkey library typosquat): passkeys-react@1.0.1 runs a preinstall that collects hostname, username, home dir, DNS servers, cwd, and contents of /etc/passwd + /etc/hosts, and transmits over HTTPS to ltivq9rn7t7gkxho4o1micsk6bc20uoj.oastify.com. Boilerplate red-team OAST recon but the naming targets the WebAuthn / passkey React ecosystem - if you operate a passkey-based auth flow and see this in your lockfile it may indicate a targeted probe
  • Cluster I - bb-twl-k7x2 Twilio-internal dep-confusion (internal.twilio.com hostname probe): bb-twl-k7x2@1.0.0..1.0.1 runs canary.js at install that captures os.hostname(), id, hostname -I, ip addr, ls /, ls -a $HOME, and getent hosts internal.twilio.com to probe whether the install host resolves Twilio's internal DNS. It searches for _auth/_authToken/password tokens in .npmrc across HOME//root//usr/etc//etc, hits the AWS instance metadata endpoint for IAM role info, and exfils over unencrypted HTTP to http://whstool.brkd.no/cb53e6db-e043-4383-89e9-853c9088ee5d/. If you operate at Twilio and see this in a lockfile, the operator has already confirmed your build host can resolve internal.twilio.com and may have your .npmrc auth tokens - escalate to internal security immediately
  • Cluster J - @telekom-ods/react-ui-kit Deutsche Telekom internal-scope compromise (2 versions, /etc/shadow read attempt): @telekom-ods/react-ui-kit@2.6.0 and @2.6.9 execute a shell command that reads /etc/passwd, /etc/hosts, and conditionally /etc/shadow, embeds username and hostname in the callback URL, and beacons to d9t83osijf9n1gb62e4gxfioysijywqww.oast.me. Publisher metadata matched legitimate prior releases - the advisory notes this looks like a compromised maintainer account or supply-chain injection, not a simple typosquat. If you operate at Deutsche Telekom or consume @telekom-ods/* scoped packages, treat any host that installed 2.6.0 or 2.6.9 as having exposed local system state; check whether /etc/shadow was readable to the installing user and rotate anything hash-derivable from it
  • Cluster K - verify-cli + @assetshop/verify-cli dep-confusion recon pair: verify-cli@99.0.0 runs preinstall that base64-encodes /etc/passwd, /etc/hosts, /etc/shadow (if readable) plus whoami/hostname/id, POSTs to 5f8a1ed70fb7761d678agw9bucryyyyyb.oast.site. @assetshop/verify-cli@99.0.0..99.0.1 is the scoped sibling - collects username/hostname/OS/arch/cwd/homedir/Node version, HTTPS-GETs to 5f8a1ed70fb7761d678agw9bapayyyyyb.oast.site and also fires a DNS query ${user}.${hostname}.assetshop-verify-cli.<oast-host> to force internal-name resolution against a private registry. If you use @assetshop/* as an internal npm scope, escalate
  • Cluster L - dakumangalsingh Java-Robot Windows RAT with jpackage wrapper (dakumangalsingh_virus 08-11 sibling): dakumangalsingh@1.0.0..1.1.0 (versionless-boilerplate on 08-11 as dakumangalsingh_virus) ships DakuMangalSingh.exe, a jpackage-wrapped native launcher that embeds a virus.jar with Java-Robot screen-capture + keystroke/mouse-input synthesis, host fingerprinting, HKCU+startup-shortcut persistence, and an anti-forensics cleanup batch. Postinstall auto-executes on Windows. Any Windows workstation that pulled the package must be treated as having a persistent screen-capture RAT and re-imaged
  • Cluster M - Massive random-name npm flood (~100+ boilerplate packages, behaviour uncharacterised): A single-day burst of ~100 packages with random-looking names (hgdvfuflnb, cvbniydplwe3, nhdxzthponv5, khanbmnxls, mnzjgxciwadk, hcfguyfrmblp, bgncvhferucfds, cxcbdjxcmncvfg2, dhjksficgwu2, chmjdsidwlf5, csbcldfvivwfgd4, bmgki3g6fh3, xhjckswqivb, hngfykuvgh4, jhkxcixudnvm1, mnchfnvbue1, cjdfswifuem3, bcnfjndwbkf2, hfkcdyuwbdx1, nhdxzthponv5, dhjksficgwu2, vlbhvgovbbhfab, hlksdcixycvf, truecxikdsal, clxofwfjskaz7, cvmbxcjiasdg, mnzjgxciwadk, hxckdoeaqjlc8, cvjwyinkpas, vczxijghsvizu4, mnhdjoweuq, cvbmxiowkwqla6, cvvkshuelwiu, khanbmnxls, bgzxcuite2, nihzvdeowx5, bgncvhferucfds, mobicwkgjmx, hcfguyfrmblp, xhjckswqivb, hngfykuvgh4) plus themed clusters (unitel3/unitel4/unitel, china_airlines, passport811, ms_aidc_com_tw, egypt0811, yangming708/yangming8, mobicommn/mobicwkgjmx/mnmobicom, airdzticket/dzvchorehui2/dzcvhfruwluwe, mnteckets, egair0810, kanyut, thundertiger, prezdentkxheiw). All carry boilerplate CWE-506 ("any computer that has this package installed or running should be considered fully compromised") without a differentiated behavioural analysis. Naming themes suggest either a large automated npm spam / typosquat flood or a coordinated multi-target dep-confusion probe against Taiwan/aviation/telecom infrastructure. Blast radius per package is not fully characterised - treat each as capable of the same credential-theft / remote-shell behaviour as the fully-analysed batch members until Socket/OpenSSF post samples
  • *Cluster N - `@noxzacode/ + noxleys operator cluster (3 packages, boilerplate CWE-506)**: @noxzacode/eslint-config@>=0, @noxzacode/libsignal-node@>=0, and noxleys@>=0 (unscoped sibling) all carry only boilerplate CWE-506 text but the naming and same-day publication implies one operator. libsignal-node is a Signal Protocol library typosquat; eslint-config` is generic. Treat as capable of the same credential-theft behaviour as fully-analysed batch members
  • *Cluster O - `@bikli/ operator cluster (5 packages, boilerplate CWE-506)**: @bikli/bikli, biklirouter, bikliwrapper, biklimaster, @bikli/cli published same-day - single operator staging both scoped (@bikli/) and unscoped (bikli`) forms. Boilerplate CWE-506 - behavioural profile unclear

What to do

  1. 1Grep every lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml) for the full 2026-08-12 package list below
  2. 2For any Cluster A match (permit2, camelot-ammv2-core, camelot-ammv2-periphery, boring-vault, augustdigital-sdk, upshift-finance, upshift-config): assume every AWS credential, SSH key, .npmrc/.netrc token, Kubernetes config, Docker config, blockchain keystore (Foundry / Solana / Sui / Anchor / NEAR / gcloud), and every process.env value matching KEY/TOKEN/SECRET/PRIVATE/MNEMONIC/AWS/BEARER/API/INFURA/ALCHEMY has been exfiltrated. Rotate every credential accessible to the host during the exposure window, drain every wallet whose private key or seed phrase lived on the host, and re-image the host from bare metal. Correct the typo to the intended package (@uniswap/permit2-sdk for Permit2; camelot-amm-v2-* under the real Camelot scope; boring-vault maps to Veda's BoringVault repo; @augustdigital/sdk for August Digital). The mssjeep843 npm account published camelot + boring-vault together - block that publisher's future releases in your private mirror
  3. 3For Cluster B matches (envpack-conf, tailwind-form-templates): block outbound traffic to public Ethereum RPC endpoints (mainnet.infura.io, cloudflare-eth.com, rpc.ankr.com/eth, eth.llamarpc.com, ethereum-rpc.publicnode.com) from your build hosts - the malware needs those to fetch the C2 rendezvous transactions. Kill any Node process holding a connection to the two staged IPs. Rotate every credential on the host, correct the typo (pkg-conf for envpack-conf; @tailwindcss/forms for tailwind-form-templates). Because the C2 rendezvous point is the Ethereum wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, taking down staged IPs does not neutralise future rotations - a private-mirror block on both package names is more durable than a network IOC block
  4. 4For svelte-kit-vim / kit-map-vim matches (Cluster C - map-streak-kit family day-4): same remediation as the 2026-08-08 map-streak-kit original. Re-image the affected Linux host from bare metal, rotate every SSH key on the host, rotate every credential stored in env/config files, remove any systemd unit created in the exposure window. Fourth consecutive daily drop - the naming register now covers <framework>-<editor>-kit, kit-<editor>-map, <framework>-kit-<editor>, and kit-map-<editor>; block that morphology in your name-scanner
  5. 5For sui-gql / bcs-compact matches (Cluster D - Sui typosquat day-2): uninstall, correct the typo to the real @mysten/sui / @mysten/bcs, and treat as capable of the same wallet-key theft / credential-exfil behaviour as Cluster A until Socket or OpenSSF post the malicious-package sample
  6. 6*For any `@years17/, @years18/, @years19/, @years20/` match (Cluster E - n8n red-team mass drop with SSH backdoor): immediately audit ~/.ssh/authorized_keys on every affected host for the pwn@kali key* and remove it; kill any n8n process (module-load-time payload runs "inside n8n's main process with no sandbox" per the advisory); rotate every credential the n8n workflows had access to (n8n typically stores API tokens for external SaaS integrations in ~/.n8n/config - treat every one as exfiltrated); block outbound to jasabersama.id and audit for any TLS-validation-disabled HTTPS calls in the exposure window. Re-image the host if you can spare it - the module-load payload notes it runs unsandboxed inside n8n, so the operator had unrestricted access to any secret n8n held in memory during the exposure window
  7. 7For internallib_v756 / internallib_v392 matches (Cluster F - bare RFC1918 reverse shell): kill any process holding a TCP connection to 10.0.74.63:4444, uninstall, and (if you operate at whatever org owns 10.0.74.0/24 internally) escalate immediately - the operator is running a listener inside your internal network. Configure .npmrc scope-to-registry mapping so internallib and internallib_v* names resolve only from your private mirror, or (better) reserve the name on the public registry so an attacker cannot squat it
  8. 8For mcp-util-helpers matches (Cluster G - webhook.site R-shell channel): kill any Node process still running the preinstall, delete /tmp/.mcp-util-setup, rotate every credential env var + SSH key + AWS credential + Kubernetes/Docker config on the host, block outbound to the webhook.site endpoint. The response-body R-shell means any host that installed the package could have been running attacker-supplied commands for the full window until scanner detection - treat the host as fully compromised and re-image
  9. 9For passkeys-react matches (Cluster H): uninstall, correct to the real passkey React library your app was using (@passkey-web/react, webauthn-json, @simplewebauthn/browser, etc), and note the operator has exfiltrated your /etc/passwd, /etc/hosts, DNS server list, hostname, username, and cwd via HTTPS - rotate what you can and audit for follow-up probes
  10. 10For bb-twl-k7x2 matches (Cluster I - Twilio internal-scope probe): if you operate at Twilio, assume the operator has confirmed your build host resolves internal.twilio.com and has your .npmrc _auth/_authToken values + AWS instance-metadata IAM role info. Rotate every credential the exfil could have captured, escalate to internal security, and block outbound HTTP to whstool.brkd.no
  11. 11For @telekom-ods/react-ui-kit matches (Cluster J - Deutsche Telekom internal-scope compromise): if you operate at Deutsche Telekom or consume @telekom-ods/* internal packages, treat versions 2.6.0 and 2.6.9 as evidence of a maintainer-account or CI/CD compromise, not a typosquat - escalate to internal security to confirm whether the compromise is scoped to just those two versions or whether the operator has push access to other releases. Rotate the maintainer account credentials, audit npm publish history under the account, and check whether /etc/shadow was readable by the installing user (rotating anything hash-derivable from it)
  12. 12For verify-cli / @assetshop/verify-cli matches (Cluster K - dep-confusion recon pair): if you operate at any org using @assetshop/* as an internal scope, escalate - the DNS-fanout stub confirms internal-name resolution. Configure private-registry scope mapping so verify-cli and @assetshop/* resolve only from your mirror
  13. 13For dakumangalsingh matches (Cluster L - Java-Robot Windows RAT): re-image the affected Windows host from bare metal (postinstall auto-executes on Windows, dropping a persistent screen-capture agent). Remove the HKCU\...\Run autostart entry and the startup shortcut, treat every credential entered on the host during the exposure window as compromised, and hunt for the virus.jar payload + DakuMangalSingh.exe wrapper in ~/AppData/
  14. 14For all Cluster M/N/O boilerplate matches: uninstall, block the name in .npmrc, and prefer the full-compromise remediation posture (rotate credentials, re-image the host) unless a subsequent Socket/OpenSSF post narrows the risk. The Cluster M random-name flood is unusually large - if you rely on a private mirror that pulls from public npm on cache-miss, the incidental download surface is high; consider a name-allowlist policy for at least the next 72h while the flood settles
  15. 15For all npm installs in CI, run with --ignore-scripts as defense-in-depth to prevent postinstall/preinstall payloads (mitigates Clusters A, F, G, H, I, J, K, L - does NOT mitigate B which fires on import, C/D which are boilerplate but unknown, or E which fires at both install-time AND module-load-time)
  16. 16Verify none of the 2026-08-12 packages still resolves via your private mirror - internal caches routinely keep serving yanked tarballs after the public takedown

References

npm-2026-08-12-ghsa-malware-sweep