GitHub Advisory malware sweep - 2026-08-22 batch (PyPI `requests-crypt` = fourth `2026-08-reqcrypt` variant + PyPI `boto4` Telegram-C2 miner/worm + npm `lumen-pages-community` + `@gfe/lx-watcher` dep-confusion webhooks + `fuel-react` env exfil + `rollup-packages-node-polyfills` new JFrog-shape sibling + Postman/Okta typosquat + 3 CWE-506 no-IOC pulls)
13 new GHSA CWE-506 malware advisories in the 24h ending 2026-08-22. PyPI requests-crypt is the fourth variant of the 2026-08-reqcrypt HTTP-response exec() register; boto4 is a Telegram-bot-controlled miner + LAN worm. npm side: lumen-pages-community/@gfe/lx-watcher dep-confusion beacons, fuel-react env exfil, and a new JFrog/Lazarus rollup-family sibling.
Versions named here: 0.8.10, 0.8.11, 0.9.0, 0.9.1, 0.10.0, 0.10.1, 0.10.2, 0.10.3, 0.10.4, 0.10.5, 0.10.6, 0.10.7, 0.10.8, 0.10.9, 0.11.0, 0.11.1, 0.11.2, 0.11.3, 0.11.4, 0.11.5, 0.11.6