GitHub Advisory malware sweep - 2026-08-28 batch (PyPI `flyteplugins-*` dependency-confusion cluster (4) + PyPI `discordnv` Discord/Roblox DPAPI infostealer + PyPI `decoris` Roblox cookie stealer + PyPI `sap-quarterly-report` + `ekx-report-utils` DNS-exfil pair + PyPI `mathkitlite` PROBABLY_PENTEST + npm `@postman-cse/okta-aio-darwin-arm64` internal-namespace dependency-confusion probe + npm `@hd-team/*` cluster (8) + npm `hydration-ui-dlx` / `svelte-ui-dlx` hydration-lookalike continuation + npm `tailwindcss-*` typosquats (2) + npm long-tail CWE-506 boilerplate)
31 new GHSA malware advisories in the 24h window ending 2026-08-28. Highlights: 4 flyteplugins-* PyPI packages all published at the identical exact version 2.6.10 - a dependency-confusion probe against Union.ai / Flyte internal package namespaces; PyPI discordnv@0.8.0 steals Discord tokens plus DPAPI-decrypts Roblox cookies with full Discord-webhook + Google-Apps-Script + registry-persistence IOCs; PyPI sap-quarterly-report + ekx-report-utils share a DNS-exfil campaign; npm @postman-cse/okta-aio-darwin-arm64 reads as a Postman internal okta-aio binary namespace hit.
Versions named here: 0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.9, 0.0.10, 0.0.11, 0.0.12, 0.0.13, 0.0.14, 0.0.15, 0.0.16, 0.0.17, 0.0.19, 0.0.20, 0.0.21, 0.0.22, 0.0.23, 0.0.24, 0.0.26, 0.0.27, 0.0.29, 0.0.30, 0.0.31, 0.0.32, 0.0.33, 0.0.34, 0.0.35, 0.0.37, 0.0.38, 0.0.39, 0.0.40, 0.0.42