GitHub Advisory malware sweep - 2026-09-18 late + 2026-09-19 (npm `algamil7x.xyz` DNS-OOB scope expansion `@shared-web/utils`/`@shared-web/assets`/`@shared-runtime/modules`/`@insiderintelligence/googleadmanager` day 2; `test89-auth`/`test890-auth`/`test899-auth`/`test8999-auth` dep-confusion probe siblings of yesterday`s `test89078-auth`; on-chain Ethereum-C2 `tailwindcss-form@<=0.5.1` + `tailwindcss-forms-ui@<=0.5.2` day 2 of `0xa322E5f3...`; `@sanzoffc/baileys@<=3.0.4` newsletter-follower + unpinned `@whiskeysockets/eslint-config` github ref; `chai-as-indexed@<=7.2.8` `ipcheck-hashed.vercel.app` full-`process.env` exfil + `new Function()` RCE; `x509-escaping@0.0.0-0.0.2/1.0.1` Burp Collaborator `oastify.com` recon; `internallib_v949`, `sinful`, `openmct-heatmap`, `ac-polyfills` CWE-506; pip `py-venv-doctor@0.1.0/0.1.1` full-env-var telemetry exfil; pip `google-cloud-datacatalog-lineage-producer-client@9999`/`99999999`/`0.2.7` google-cloud-* dep-confusion sentinel; npm `keroeltop@99.99.99` malicious-domain probe)
GHSA 2026-09-18 late + 2026-09-19: 4x npm @shared-* + @insiderintelligence/* scopes at sentinel 9.9.10 extend yesterdays algamil7x.xyz DNS-OOB campaign into fresh internal-lookalike scopes (day 2, same operator); 4x test89-auth dep-confusion probes continue the test89078-auth cluster; on-chain Ethereum-C2 tailwindcss-form typosquats republish under 0xa322E5f3... (day 2); chai-as-indexed POSTs the full process.env to ipcheck-hashed.vercel.app and evals the response; pip py-venv-doctor` exfils environment variables via a fake healthcheck telemetry channel.
Versions named here: 9.9.10