GitHub Advisory malware sweep - 2026-09-23 (late) + 2026-09-24 (npm `@baanx/*` + `@insiderintelligence/componentlibrary` `oob.algamil7x.xyz` DNS-OOB day 7; `@rixxcodex/baileys` + `sea-baileys` Baileys-wave WhatsApp session-hijack extension; `pino-testkit` chai/pino/jsonspack family Function-constructor RCE; `vite-dev-launcher` `~/.gradle/caches/` sibling of yesterday`s `@vitemirrorte` mall4cloud-react RAT; pip `memoryos` maintainer-compromise infostealer + npm `@memtensor/memos-cloud-openclaw-plugin` openclaw plugin; `internallib_v657` + `internallib_v463` RFC1918 `10.0.73.186:443` curl-pipe reverse shell (new subnet vs v497/v550 `10.0.5.109`); `godzz`/`godzzz` Cloudflare-Worker + Groq API key exfil siblings; `com.apple.unityplugin.storekit` + `simplenewnpmpackage` shared `dapnhid534ch...oast.fun` recon beacons; `a-onesite`, `event-hunter`, `helpersutils-dev-tools` beacon-only probes; `hachutis` undeclared-binary trycloudflare tunnel; rubygems `wurl_show_data`)
GHSA 2026-09-23 (late) + 2026-09-24: ~25 new npm advisories + 1 pip + 1 rubygems. Day 7 of the oob.algamil7x.xyz DNS-OOB operator adds @baanx/common, @baanx/domain, and @insiderintelligence/componentlibrary. vite-dev-launcher@2.9.4 is a mall4cloud-react-RAT sibling of yesterdays @vitemirrorte. internallib_v657/v463` reverse shell to a new RFC1918 subnet.
Versions named here: 9.9.10