Feed
CriticalPublished 13 Aug 202646 packages · 87 versions

GitHub Advisory npm CWE-506 sweep - 2026-08-13 batch (`ltidisafe` GCS dep-confusion dropper ring `check-audit`+`cspell-esm`+`eslint-publish-release`+`in-install`+`knip-bun`+`resolve-audit`+`napi-raw`, `31.97.137.157:45000` bare-IP Chromium-DPAPI stealer kit `vexium-kit`+`ventra-kit`+`velora-kit`+`vortex-kit`+`copytrade-core`+`prediction-trader`, `@hzero-front-ui/*` internal-scope dep-confusion 5-package cluster with `callback.m0chan.co.uk` DNS+HTTPS beacon, `@khaznatech/*` webhook.site preinstall exfil 3-pack, `jchunt.top` telemetry-canary series `wct-st`+`tizen-webdriver-cli`, `8.135.48.40:4444` reverse-shell date-fmt masquerade pair `datefmt-util-helper`+`date-fmt-helper-xz`, `notafollower` AWS IMDSv2 credential theft, `bs58-15` base58 typosquat via `base65-15x` transitive, `@solana-js/web3` Windows PowerShell + `files.catbox.moe` RCE, `postcss-initialize-plugin` Ethereum-RPC-C2 continuation, `mutex-forge` Telegram+Slack+Ethereum-Sepolia RAT, `chai-as-reformed`+`process-live-log`+`external-process-live-log`+`minimalistic-assert-plus` Function-constructor R-shell family, `node-config-svg-contract` eval-from-URL, `nc-verify-127942`+`@jacksher/install-exec-poc` OAST recon POCs, `cilm-ui-commons` pipedream.net preinstall, ~10 boilerplate CWE-506)

Summary

~50 npm CWE-506 advisories published 2026-08-13. Headline: ltidisafe GCS dep-confusion dropper ring (7+ hollow-shell packages at v99.9.1 pinning ltidisafe as an https://ltidi.storage.googleapis.com/depenconf/ tarball to bypass npm registry review); 31.97.137.157:45000 bare-IP Chromium-DPAPI stealer kit family (vexium-kit, ventra-kit, velora-kit, vortex-kit, copytrade-core, prediction-trader - all fetch /icons/108|116 and eval() a credits field with @primno/dpapi+better-sqlite3+node-machine-id bundled for browser-cred theft); and a *`@hzero-front-ui/ 5-package internal-scope dep-confusion cluster** beaconing to callback.m0chan.co.uk`.

typosquatdependency-confusioncredential-theftcrypto-wallet-draininfostealerobfuscation
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · amazon-inspector · kam193 bad-packages
Also known as
2026-08-13 GHSA npm batch · ltidisafe GCS dropper ring · 31.97.137.157:45000 kit family · @hzero-front-ui dep-confusion probe · @khaznatech dep-confusion probe · jchunt.top telemetry-canary series
Ecosystems
npm
Packages tracked
46

What happened

On 2026-08-13, the GitHub Advisory Database published ~50 new npm CWE-506 (Embedded Malicious Code) advisories. The shape continues the pattern seen throughout August: multiple parallel operator campaigns running simultaneously - a dep-confusion dropper ring against tool namespaces, a bare-IP Chromium-DPAPI stealer kit family, two internal-scope dep-confusion probes, a blockchain-C2 loader continuation, and a long tail of one-off POC / boilerplate packages.

Cluster A - ltidisafe Google Cloud Storage dep-confusion dropper ring (7+ packages at v99.9.1)

| Package | Version | GHSA | Typosquats | |---|---|---|---| | check-audit | 99.9.1 | GHSA-xcx8-wpwx-h8f4 | generic audit/security tool | | cspell-esm | <=99.9.1 | GHSA-mpgx-7wm7-ggxm | cspell | | eslint-publish-release | 99.9.1 | GHSA-jmh4-xr6v-622w | ESLint tooling | | eslint-generate-prerelease | >=99.9.1 | GHSA-m4vp-pxj5-3j47 | ESLint tooling | | eslint-generate-release | >=99.9.1 | GHSA-wq2m-9vc9-746v | ESLint tooling | | in-install | <=99.9.1 | GHSA-5q6v-3rg4-8rf8 | dep-confusion probe | | knip-bun | 99.9.1 | GHSA-r697-xx2p-9hr4 | knip linter | | resolve-audit | 99.9.1 | GHSA-m9fv-2g5q-rhhh | dep-confusion probe | | napi-raw | 99.9.1 | GHSA-r9mm-m965-266j | napi/node-addon-api |

All packages share the identical mechanism: module.exports = {} (or empty stub) with no lifecycle scripts of their own, plus a single dependency declaration pinning ltidisafe to https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.6.x.tgz (versions 3.6.1 / 3.6.3 / 3.6.8 observed - GCS bucket owner controls which). On npm install the tarball is fetched outside npm registry review and its lifecycle scripts execute in the installer's environment. The depenconf path token (short for "dependency-confusion") and inflated 99.9.1 version make the operator's intent explicit - designed to win dep-confusion resolution against private-registry packages with the same name.

The tarball at the GCS URL is mutable - the operator can update its contents silently by re-uploading without republishing any package. Package-level block is insufficient defense; network-level block of ltidi.storage.googleapis.com is more durable, and reserving the name in your private registry is the strongest mitigation.

Cluster B - 31.97.137.157:45000 bare-IP Chromium-DPAPI stealer kit family (6 packages)

| Package | Versions | GHSA | Endpoint | |---|---|---|---| | vexium-kit | 2.0.2, 10.0.2 | GHSA-wxpv-6v7m-pcp9 | 31.97.137.157:45000/icons/116 | | ventra-kit | 1.0.2 | GHSA-9wjh-9c25-4w8p | 31.97.137.157:45000/icons/116 | | velora-kit | 12.0.2, 12.1.2 | GHSA-xw23-8m9g-4hr8 | 31.97.137.157:45000 | | @leonardo0902/vortex-kit | <=12.0.2 | GHSA-ggj6-v47w-25jr | 31.97.137.157:45000/icons/116 | | copytrade-core | <=2.3.0 | GHSA-mp75-xvjv-4p2w | 31.97.137.157:45000/icons/108 | | prediction-trader | 2.3.0 | GHSA-g7gf-2m6j-5f6q | 31.97.137.157:45000/icons/108 |

All six ship the identical loader: HTTPS-GET the bare-IP endpoint, parse JSON, pass the credits field to new Function(...) with require, process, Buffer, module in scope. The declared dependency set (@primno/dpapi for Windows DPAPI decryption of Chrome/Edge password stores, better-sqlite3 for browser Login Data reads, node-machine-id for host fingerprinting) is exactly the toolkit needed to steal Chromium browser credentials, cookies, session tokens, and MetaMask/Phantom wallet keystores from Local State files. Decoy variable names (iconDomain, getPlugin) and references to real CDNs (Cloudflare, Fastly, Akamai, CloudFront) disguise the RCE as a static-asset fetch.

The two endpoint variants (/icons/108 for copytrade/prediction-trader vs /icons/116 for the kit family) may indicate two different second-stage payloads staged for different target profiles, or two different operators sharing the same C2 host. copytrade-core and prediction-trader targeting is more DeFi-flavored (trading terminology); the -kit family (vexium, ventra, velora, vortex) targets a general browser-cred lookalike register.

Cluster C - @hzero-front-ui/* internal-scope dep-confusion 5-pack (callback.m0chan.co.uk beacon)

| Package | Version | GHSA | |---|---|---| | @hzero-front-ui/core | 99.99.99 | GHSA-3fqm-rv2m-r2mg | | @hzero-front-ui/cfg | 99.99.99 | GHSA-xw5r-5p6j-q25p | | @hzero-front-ui/themes | 99.99.99 | GHSA-5wqp-c676-3j8x | | @hzero-front-ui/c7n-ui | 99.99.99 | GHSA-87j4-2mgq-7prq | | @hzero-front-ui/hzero-ui | 99.99.99 | GHSA-4rw7-83wf-6rcm |

All five: empty module.exports = {}, install scripts base64-encode $(whoami):$(hostname):$(pwd):$npm_package_name, transmit to subdomains of callback.m0chan.co.uk via HTTPS and DNS fanout. The m0chan.co.uk callback host + coordinated 5-package publish + shared version (99.99.99) + shared exfil payload = one operator running a dep-confusion probe against a @hzero-front-ui/* internal scope. The naming targets Hzero (an open-source enterprise middleware platform whose front-end packages typically live under private scopes).

Cluster D - @khaznatech/* internal-scope webhook.site preinstall exfil 3-pack

| Package | Version | GHSA | |---|---|---| | @khaznatech/core | 99.0.0 | GHSA-76xq-9jp7-j7rm | | @khaznatech/common | 99.0.0 | GHSA-f23c-rm7x-p3c2 | | @khaznatech/utils | 99.0.0 | GHSA-x69g-rr7m-w288 |

All three: preinstall collects hostname + working-directory basename, HTTPS-POSTs to a hardcoded webhook.site capture endpoint. Coordinated 3-package publish + shared 99.0.0 version + shared exfil pattern = same-operator dep-confusion probe against a @khaznatech/* internal scope.

Cluster E - jchunt.top install-time telemetry canary series

| Package | Versions | GHSA | Endpoint | |---|---|---|---| | wct-st | >=1.0.0 | GHSA-6r3v-5c9p-jv7v | bhvte4h4.instances.poc.jchunt.top/wct-st | | tizen-webdriver-cli | 1.0.0 | GHSA-cffv-ggq7-fw2q | 8kq1s58l.instances.poc.jchunt.top/tizen-webdriver-cli |

Both run a postinstall that collects hostname/platform/arch/Node-version/package-name and POSTs to a per-package *.instances.poc.jchunt.top endpoint (3s timeout, silent error suppression). The poc.jchunt.top sub-domain naming + per-package sub-subdomain routing + narrow exfil scope suggests a single research canary operator - series continues into 08-14 with xrblocks-mcp and preinstall-hook-webhook-callback-demo.

Cluster F - 8.135.48.40:4444 reverse-shell date-fmt masquerade pair

| Package | Versions | GHSA | |---|---|---| | datefmt-util-helper | 1.0.0, 1.0.1 | GHSA-3w9h-7mv3-vfh5 | | date-fmt-helper-xz | <=1.0.4 | GHSA-3553-96xv-fjg2 |

Both ship a postinstall reverse shell to hardcoded VPS 8.135.48.40:4444 - date-fmt-helper-xz adds Bash and Python fallback loaders plus HTTP failure telemetry back to the operator. Both masquerade as date-formatting utilities; the shared C2 host + shared reverse-shell primitive + name morphology overlap (datefmt/date-fmt) suggests one operator staging two variants.

Cluster G - notafollower AWS EC2 IMDSv2 credential theft (12 versions)

| Package | Versions | GHSA | |---|---|---| | notafollower | 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11 | GHSA-8mmx-gvp3-q5f5 |

Preinstall + postinstall both request IMDSv2 tokens from 169.254.169.254, enumerate IAM roles, extract AccessKeyId/SecretAccessKey/SessionToken, exfiltrate to a hardcoded HTTPS destination. Version 1.0.4 has the placeholder YOUR_COLLAB still baked in - indicating an early-development artifact accidentally published to the public registry (the operator continued to iterate through 1.0.11 anyway).

Cluster H - bs58-15 base58 typosquat via base65-15x transitive

| Package | Versions | GHSA | |---|---|---| | bs58-15 | <=6.0.1 | GHSA-pc6p-3869-9j4f |

Impersonates bs58 (base58 encoding library used across Solana/Ethereum/Bitcoin tooling); its package.json repository/homepage/bugs fields point at the legitimate cryptocoinjs/bs58 project. Pulls in a base65-15x transitive dep (lookalike of base-x) which executes at module-load-time. Any codebase that mistypes bs58 as bs58-15 runs attacker code inside the import graph.

Cluster I - @solana-js/web3 Windows PowerShell + files.catbox.moe RCE

| Package | Versions | GHSA | |---|---|---| | @solana-js/web3 | <=1.91.3 | GHSA-v6v8-vghm-gj9m |

Counterfeits @solana/web3.js, falsely attributes authorship to Solana Labs. Windows-only postinstall chain: base64-encoded PowerShell + hex-escaped strings + AMSI bypass + binary download from files.catbox.moe. Non-Windows hosts inert.

Cluster J - Ethereum-RPC-C2 register continuation postcss-initialize-plugin

| Package | Versions | GHSA | |---|---|---| | postcss-initialize-plugin | <=3.0.4 | GHSA-v5q4-xw6r-qm2r |

Queries Ethereum RPC endpoints at module-load to retrieve attacker instructions embedded in blockchain transactions, then spawns Node child processes to execute them. Same C2-over-blockchain pattern as 08-12 Cluster B envpack-conf / tailwind-form-templates - operator population using public blockchains for C2 is growing.

Cluster K - mutex-forge multi-channel loader (Telegram + Slack + Ethereum Sepolia)

| Package | Versions | GHSA | |---|---|---| | mutex-forge | 2.0.1, 2.0.2 | GHSA-v9j8-gcr7-95v6 |

Masquerades as mutex/semaphore library. Hidden loader stages recon host, exfil to Telegram + Slack channels, retrieve second-stage payloads from Ethereum Sepolia smart contracts (testnet C2 rendezvous), establish persistent C2. Multi-channel loader is unusual - most current npm samples use a single exfil channel.

Cluster L - Function-constructor R-shell family (4 packages)

| Package | Versions | GHSA | Loader | |---|---|---|---| | process-live-log | <=11.5.2 | GHSA-h9wf-jh2r-67ww | bare-IP credits field + new Function(...) | | external-process-live-log | 13.5.2 | GHSA-5q78-2f9h-xv69 | bare-IP credits field + new Function(...) | | chai-as-reformed | <=1.2.0 | GHSA-2mjx-w8vq-qwgp | jsonstorage.net cookie field + new Function.constructor | | minimalistic-assert-plus | <=1.1.7 | GHSA-35q8-7f5w-wv67 | detached child fetch + eval() with real require |

All four: hollow package + module-load / detached-child fetch + Function/eval execution of remote content with full Node context. Same operator pattern as Cluster B but different infrastructure - the credits field name in process-live-log / external-process-live-log matches the Cluster B loader signature exactly, suggesting either the same operator running multiple infrastructure lanes or copycats. chai-as-reformed's jsonstorage.net variant swaps the storage backend but keeps the Function.constructor execution model.

Cluster M - OAST recon POCs (2 packages, oastify.com Burp Collaborator)

| Package | Versions | GHSA | Beacon | |---|---|---|---| | nc-verify-127942 | 1.0.0 | GHSA-phh7-pw76-hr8h | nc-verify-127942.owoemjgpf2c4qxqet92hexzvym4dsq6skvoa2cr.oastify.com | | @jacksher/install-exec-poc | 1.0.0, 1.0.2 | GHSA-pf2f-2wpf-5qfx | jobzq12beck611luewfsf8yyepkg86wv.oastify.com/postinstall-fired |

Both self-labeled RCE-verification POCs, both execute unconditionally on install. @jacksher/install-exec-poc establishes a shell-to-network execSync curl primitive beyond bare DNS/HTTPS.

Cluster N - node-config-svg-contract eval-from-URL (rest-icon-handler.store)

| Package | Versions | GHSA | |---|---|---| | node-config-svg-contract | 1.0.0 | GHSA-wc9r-p4qf-2qw7 |

getPlugin/setPlugin/getPluginExten reconstruct https://rest-icon-handler.store/icons/ at runtime from fragmented string constants, fetch content, eval(JSON.parse(body)). Fragmented-constant URL construction defeats static scanners.

Cluster O - cilm-ui-commons pipedream.net preinstall exfil (full-package.json)

| Package | Versions | GHSA | |---|---|---| | cilm-ui-commons | 1.1.0 | GHSA-fxmj-23mp-f362 |

Preinstall collects host identity + full package.json contents and POSTs to a hardcoded pipedream.net webhook. Full-package.json exfil enables the operator to enumerate every dep in your project - hunt for follow-up typosquats against your private-registry names in the next 24-72h.

Cluster P - debug-proxy-chrome-devtools webhook exfil (2 versions)

| Package | Versions | GHSA | |---|---|---| | debug-proxy-chrome-devtools | 1.0.1, 1.0.2 | GHSA-6f7w-v259-jq39 |

Postinstall shell-captures whoami/hostname and transmits to external webhook. Boilerplate credential-recon.

Boilerplate CWE-506 (uncharacterised)

| Package | Versions | GHSA | |---|---|---| | ai-analyzer | 1.0.0..1.0.19 (20 versions) | GHSA-fqv8-262c-j5xv | | root-locator | >=0 | GHSA-57g4-vm3v-74xg | | source-analyzer | >=0 | GHSA-p68g-6893-44r8 | | react-shield | >=0 | GHSA-gmx3-395m-pwc2 | | path-match-js | >=0 | GHSA-cgj7-7fj2-6r74 |

Standard "any computer that has this package installed or running should be considered fully compromised" boilerplate. Behavioural profile not published - treat as capable of the same credential-theft / R-shell behaviour as the fully-analysed batch members.

Registry state

All ~50 packages yanked or security-holding-replaced from npm during the 2026-08-13 takedown window. Private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs before takedown will keep serving the malicious versions.

Related tracked activity

  • Ethereum-RPC-C2 register (Clusters J, K): continues 08-12 Cluster B envpack-conf/tailwind-form-templates. Growing operator population using public blockchains as C2 rendezvous.
  • Function-constructor R-shell family (Cluster L): same loader signature (credits field) as 08-13 Cluster B 31.97.137.157:45000 kit family - potentially the same operator running multiple infrastructure lanes.
  • jchunt.top telemetry-canary series (Cluster E): continues into 08-14 with xrblocks-mcp and preinstall-hook-webhook-callback-demo.
  • Discovery credits: GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, amazon-inspector, kam193 bad-packages. No named threat actor.

Affected packages (46)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • Cluster A - ltidisafe Google Cloud Storage dep-confusion dropper ring (7+ packages at v99.9.1): check-audit@99.9.1, cspell-esm@<=99.9.1, eslint-publish-release@99.9.1, eslint-generate-prerelease@>=99.9.1, eslint-generate-release@>=99.9.1, in-install@<=99.9.1, knip-bun@99.9.1, resolve-audit@99.9.1, and napi-raw@99.9.1 are hollow shells (module.exports = {}) whose only real payload is a package.json dependency declaration pinning ltidisafe to https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.6.x.tgz - an anonymous GCS bucket outside npm registry review. On npm install the tarball is fetched and its lifecycle scripts run in the installer's environment. The depenconf bucket path token, inflated 99.9.1 version (designed to win dep-confusion resolution against private-registry packages), and the deliberate targeting of legitimate tool namespaces (cspell, eslint-*, knip, napi, resolve) are all consistent with one operator running a dep-confusion probe against organisations whose internal scopes contain packages with these names. The tarball is mutable - the operator can update it silently by re-uploading to the GCS bucket without republishing the package
  • Cluster B - 31.97.137.157:45000 bare-IP Chromium-DPAPI stealer kit family (6 packages, Function-constructor RCE + browser-credential stealer bundle): vexium-kit@2.0.2,10.0.2, ventra-kit@1.0.2, velora-kit@12.0.2,12.1.2, @leonardo0902/vortex-kit@<=12.0.2, copytrade-core@<=2.3.0, and prediction-trader@2.3.0 all share the identical loader pattern: HTTPS-GET 31.97.137.157:45000/icons/108 (or /icons/116), parse response JSON, pass the credits field to new Function(...) with full Node context (require, process, Buffer, module). The declared dependency set - @primno/dpapi (Windows DPAPI decryption for Chrome/Edge password stores), better-sqlite3 (browser login DB read), node-machine-id (host fingerprint) - is exactly the toolkit needed to steal Chromium browser credentials, cookies, session tokens, and wallet keystores from the Local State / Login Data files. The iconDomain/getPlugin variable naming and decoy CDN references (Cloudflare, Fastly, Akamai, CloudFront) disguise the RCE as a static-asset fetch. Any developer who imports and calls the default export on Windows should be treated as having a browser-credential and wallet-key stealer running unattended, with the operator able to rotate the payload at will
  • *Cluster C - `@hzero-front-ui/ internal-scope dep-confusion 5-pack (callback.m0chan.co.uk beacon)**: @hzero-front-ui/core@99.99.99, @hzero-front-ui/cfg@99.99.99, @hzero-front-ui/themes@99.99.99, @hzero-front-ui/c7n-ui@99.99.99, and @hzero-front-ui/hzero-ui@99.99.99 are all empty-export shells whose install scripts base64-encode $(whoami):$(hostname):$(pwd):$npm_package_name and beacon to attacker-owned subdomains of callback.m0chan.co.uk via both **HTTPS** and **DNS**. The 99.99.99 version + scoped namespace + coordinated same-day publish confirms a dep-confusion probe against orgs using @hzero-front-ui/ as an internal scope. If you operate at Hzero (or consume the legitimate @hzero/front-ui- internal packages), assume the operator has confirmed your build host resolves the scope and rotate any .npmrc _auth/_authToken` values
  • *Cluster D - `@khaznatech/ internal-scope webhook.site preinstall exfil 3-pack**: @khaznatech/core@99.0.0, @khaznatech/common@99.0.0, and @khaznatech/utils@99.0.0 each run a preinstall that collects hostname + working-directory basename and HTTPS-POSTs to a hardcoded webhook.site capture endpoint. Same version + same-day publish + same exfil pattern - single-operator dep-confusion probe against @khaznatech/*` internal scope. Smaller exfil surface than Cluster C (no username, no package name) - still enough to confirm internal-name resolution
  • *Cluster E - jchunt.top install-time telemetry-canary series (2+ packages, `.instances.poc.jchunt.top beacon)**: wct-st@>=1.0.0 (typosquats deprecated web-component-tester, beacons to bhvte4h4.instances.poc.jchunt.top/wct-st) and tizen-webdriver-cli@1.0.0 (dep-confusion against Tizen dev tooling, beacons to 8kq1s58l.instances.poc.jchunt.top/tizen-webdriver-cli) both run a postinstall that collects hostname/platform/arch/Node-version/package-name and POSTs to a package-specific *.instances.poc.jchunt.top endpoint with 3s timeout and silent error suppression. Consistent with a single research-canary operator running per-package poc.jchunt.top sub-domains - continues into 08-14 with xrblocks-mcp and preinstall-hook-webhook-callback-demo`
  • Cluster F - 8.135.48.40:4444 reverse-shell date-fmt masquerade pair: datefmt-util-helper@1.0.0,1.0.1 and date-fmt-helper-xz@<=1.0.4 each ship a postinstall reverse shell to hardcoded VPS 8.135.48.40:4444; the date-fmt-helper-xz variant adds Bash and Python fallback loaders and posts install-failure telemetry back via HTTP. Both masquerade as date-formatting utilities but connect a full interactive /bin/sh to the operator's C2 at install-time on the installing user's UID. Any Linux/Mac host that pulled either package must be treated as having had an interactive shell reachable to the operator during the exposure window - re-image and rotate every credential accessible from the host
  • Cluster G - notafollower AWS EC2 IMDSv2 credential theft (1 package, 12 versions): notafollower@1.0.0..1.0.11 (12 consecutive versions) preinstall + postinstall both fire, requesting IMDSv2 tokens from 169.254.169.254, enumerating IAM roles, extracting AccessKeyId/SecretAccessKey/SessionToken, and exfiltrating to a hardcoded HTTPS destination (v1.0.4 has the placeholder YOUR_COLLAB still baked in, indicating an early-development artifact accidentally published). Any EC2 / ECS / CodeBuild / self-hosted-EC2-CI host that pulled the package must be treated as having had its IAM role credentials exfiltrated - rotate the role, revoke session tokens, and audit CloudTrail for the exposure window
  • Cluster H - bs58-15 base58 typosquat via base65-15x transitive: bs58-15@<=6.0.1 impersonates the widely-used bs58 base58 encoding library (its package.json repository/homepage/bugs fields point at the legitimate cryptocoinjs/bs58 project despite unrelated authorship) and pulls in a base65-15x transitive dep (lookalike of base-x) which executes at module-load-time. Any Solana / Ethereum / cryptocurrency codebase that mistypes bs58 as bs58-15 runs the attacker's code inside the import graph
  • Cluster I - @solana-js/web3 Windows PowerShell + files.catbox.moe RCE: @solana-js/web3@<=1.91.3 counterfeits @solana/web3.js, falsely attributes authorship to Solana Labs, and postinstalls a Windows-only PowerShell chain that base64-encodes commands, hex-escapes strings, applies AMSI bypass, and downloads a binary payload from files.catbox.moe. On non-Windows hosts the package is inert - on Windows it executes RCE at install-time. Rotate Windows host credentials and re-image if this appears in a lockfile
  • Cluster J - Ethereum-RPC-C2 register continuation postcss-initialize-plugin: postcss-initialize-plugin@<=3.0.4 queries Ethereum RPC endpoints at module-load time to retrieve attacker-controlled instructions embedded in blockchain transactions, then executes them via spawned Node child processes. Same C2-over-blockchain pattern as 08-12 Cluster B (envpack-conf, tailwind-form-templates) - block outbound Ethereum RPC (mainnet.infura.io, cloudflare-eth.com, rpc.ankr.com/eth, eth.llamarpc.com, ethereum-rpc.publicnode.com) from build hosts as defense-in-depth
  • Cluster K - mutex-forge multi-channel loader (Telegram + Slack + Ethereum Sepolia): mutex-forge@2.0.1,2.0.2 masquerades as a mutex/semaphore library but ships hidden loader stages that recon the host, exfiltrate to Telegram and Slack channels, retrieve second-stage payloads from Ethereum Sepolia smart contracts (testnet C2 rendezvous), and establish persistent command-and-control. Third-in-a-row blockchain-C2 register alongside 08-12 Cluster B and 08-13 Cluster J - the operator population using public blockchains for C2 is growing
  • Cluster L - Function-constructor R-shell family (4 packages, hardcoded bare-IP / jsonstorage.net eval loaders): process-live-log@<=11.5.2 and external-process-live-log@13.5.2 each HTTPS-fetch from a hardcoded bare-IP endpoint and pass the response credits field into new Function(...) (same loader pattern as Cluster B but not confirmed same infrastructure); chai-as-reformed@<=1.2.0 fetches JSON from a concealed jsonstorage.net URL and passes a cookie field to new Function.constructor (Function-constructor variant of the eval-from-URL pattern); minimalistic-assert-plus@<=1.1.7 spawns a detached Node child that fetches and eval()s attacker-supplied JavaScript with the real require in scope. All four are the same operator pattern: hollow-package + module-load / detached-child fetch + Function/eval execution of remote content
  • Cluster M - OAST recon POCs (2 packages, oastify.com Burp Collaborator): nc-verify-127942@1.0.0 (postinstall install-cb.js HTTPS-GET + DNS-lookup to a Burp Collaborator nc-verify-127942.<random>.oastify.com subdomain, self-labeled RCE-verification POC) and @jacksher/install-exec-poc@1.0.0,1.0.2 (postinstall beacon.js executing child_process.execSync curl to jobzq12beck611luewfsf8yyepkg86wv.oastify.com/postinstall-fired - creates a shell-to-network exec primitive). Both self-identify as PoCs but execute unconditionally on install - the POC label is not mitigating
  • Cluster N - node-config-svg-contract eval-from-URL (rest-icon-handler.store): node-config-svg-contract@1.0.0 disguises malware as an SVG/icon CDN helper - getPlugin/setPlugin/getPluginExten reconstruct https://rest-icon-handler.store/icons/ at runtime from fragmented string constants (protocol / subdomain / domain / path), fetch content, and execute via eval(JSON.parse(body)). Fragmented-constant URL construction defeats static string-scanners
  • Cluster O - cilm-ui-commons pipedream.net preinstall exfil (1 package): cilm-ui-commons@1.1.0 preinstall collects host identity + full package.json contents and POSTs to a hardcoded pipedream.net webhook. The full-package.json exfil is atypical - the operator can enumerate every dep in your project (potentially identifying private-registry names to typosquat next), not just the host fingerprint
  • Cluster P - debug-proxy-chrome-devtools webhook exfil pair (2 versions): debug-proxy-chrome-devtools@1.0.1,1.0.2 postinstall shell-captures whoami/hostname and transmits to an external webhook. Boilerplate credential-recon
  • Boilerplate CWE-506 (~10 packages, uncharacterised behaviour): ai-analyzer@<=1.0.19 (20 versions), root-locator@>=0, source-analyzer@>=0, react-shield@>=0, path-match-js@>=0, and other unclassified drops carry only the standard "any computer that has this package installed or running should be considered fully compromised" text without a differentiated behavioural analysis. Treat as capable of the same credential-theft / R-shell behaviour as the fully-analysed batch members until Socket/OpenSSF post samples

What to do

  1. 1Grep every lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml) for the full 2026-08-13 package list below
  2. 2For any Cluster A match (ltidisafe GCS dropper: check-audit, cspell-esm, eslint-publish-release, eslint-generate-prerelease, eslint-generate-release, in-install, knip-bun, resolve-audit, napi-raw): the fetched GCS tarball is mutable - assume its lifecycle scripts have already run in your installer's environment and treat the host as fully compromised (rotate every credential accessible to the install-time UID, re-image the host). Configure .npmrc scope-to-registry mapping so check-audit/cspell-esm/eslint-publish-release/eslint-generate-prerelease/eslint-generate-release/in-install/knip-bun/resolve-audit/napi-raw resolve only from your private mirror, or reserve the names on public npm so the operator cannot re-squat. Block outbound to ltidi.storage.googleapis.com from build hosts
  3. 3For any Cluster B match (vexium-kit, ventra-kit, velora-kit, vortex-kit, @leonardo0902/vortex-kit, copytrade-core, prediction-trader): if the affected host is a Windows workstation, treat every browser-saved password / cookie / session token / wallet keystore in Chromium/Edge/Brave Local State and Login Data files as exfiltrated. Rotate every credential ever entered into a Chromium-based browser on the host (banking, SaaS, GitHub session, cloud-console logins), drain every wallet whose keystore lived in Chromium-tied extensions (MetaMask, Phantom, Solflare), and re-image. Block outbound to 31.97.137.157:45000 at the network edge - the operator can rotate the second-stage payload at will so a package-block-only remediation is not enough
  4. 4For any Cluster C match (@hzero-front-ui/core, @hzero-front-ui/cfg, @hzero-front-ui/themes, @hzero-front-ui/c7n-ui, @hzero-front-ui/hzero-ui): if you operate at Hzero or consume @hzero-front-ui/*/@hzero/front-ui-* internal packages, escalate to internal security - the operator has confirmed your build host resolves the scope and exfiltrated whoami:hostname:pwd:package-name. Block outbound to callback.m0chan.co.uk at the network edge, configure private-registry scope mapping so @hzero-front-ui/* resolves only from your mirror
  5. 5For any Cluster D match (@khaznatech/core, @khaznatech/common, @khaznatech/utils): if you operate at Khaznatech or consume @khaznatech/* internal packages, escalate - the operator has confirmed internal-scope resolution and has your hostname + working directory. Configure private-registry scope mapping
  6. 6For any Cluster E match (wct-st, tizen-webdriver-cli): uninstall, correct the typo (web-component-tester for wct-st; the real Tizen WebDriver CLI you were after for tizen-webdriver-cli), block outbound to *.instances.poc.jchunt.top at the network edge. Data exfiltrated is limited (hostname/platform/arch/Node version/package name) but confirms the operator can enumerate hosts pulling either package
  7. 7For any Cluster F match (datefmt-util-helper, date-fmt-helper-xz): kill any process holding a TCP connection to 8.135.48.40:4444, re-image the affected Linux/Mac host from bare metal (postinstall opened an interactive shell to the operator during the exposure window), and rotate every credential accessible to the installing user during that window. Block outbound to 8.135.48.40 at the network edge
  8. 8For any notafollower match (Cluster G - AWS IMDSv2 credential theft): if the affected host runs in EC2, ECS, CodeBuild, or self-hosted CI on EC2, revoke the IAM role's session tokens immediately, rotate the instance profile, and audit CloudTrail for any API call made using the exfiltrated credentials during the exposure window. Enforce IMDSv2-only mode with a hop limit of 1 on all instances (blocks container-escape access to the metadata service) as durable defense
  9. 9For bs58-15 matches (Cluster H): uninstall, correct the typo to real bs58, and audit the immediate base65-15x transitive dep - the module-load-time payload runs inside every import chain that transitively depends on the typosquat. Rotate any base58-derived key material processed on the host during the exposure window (Solana / Ethereum / Bitcoin addresses)
  10. 10For @solana-js/web3 matches (Cluster I - Windows PowerShell + catbox.moe): re-image the affected Windows host, block outbound to files.catbox.moe at the network edge, correct the typo to the real @solana/web3.js. Non-Windows hosts are inert but should still uninstall
  11. 11For postcss-initialize-plugin / mutex-forge matches (Clusters J, K - blockchain-C2 loaders): block outbound to public Ethereum mainnet + Sepolia RPC endpoints (mainnet.infura.io, cloudflare-eth.com, rpc.ankr.com/eth, eth.llamarpc.com, ethereum-rpc.publicnode.com, sepolia.infura.io, rpc.sepolia.org) from build hosts. Because the C2 rendezvous point is a blockchain wallet/contract, taking down staged IPs does not neutralise the loader - a private-mirror block on the package name is more durable than a network IOC block
  12. 12For Cluster L matches (process-live-log, external-process-live-log, chai-as-reformed, minimalistic-assert-plus): uninstall and treat as full-compromise remediation (rotate credentials, re-image host) - each package eval()s or new Function()s attacker-controlled content with full Node context so the operator had unrestricted RCE during any import
  13. 13For Cluster M/N/O/P matches (OAST POCs, node-config-svg-contract, cilm-ui-commons, debug-proxy-chrome-devtools): uninstall, block outbound to oastify.com, pipedream.net, rest-icon-handler.store from build hosts, and rotate the credentials the exfil could have captured. cilm-ui-commons's full-package.json exfil means the operator has your project's complete dependency list - hunt for follow-up typosquats against your private-registry names in the next 24-72h
  14. 14For all boilerplate CWE-506 matches (ai-analyzer, root-locator, source-analyzer, react-shield, path-match-js, etc): uninstall, block the name in .npmrc, and prefer the full-compromise remediation posture (rotate credentials, re-image the host) unless a subsequent Socket/OpenSSF post narrows the risk
  15. 15For all npm installs in CI, run with --ignore-scripts as defense-in-depth to prevent postinstall/preinstall payloads (mitigates Clusters A/D/E/F/G/M/O/P - does NOT mitigate B/H/I/J/K/L which fire on import, or C which fires at install-time regardless of scope)
  16. 16Verify none of the 2026-08-13 packages still resolves via your private mirror - internal caches routinely keep serving yanked tarballs after the public takedown

References

npm-2026-08-13-ghsa-malware-sweep