GitHub Advisory malware sweep - ~155 npm packages (logger/tailwind/eslint/bignumber typosquats, polymarket-onchain-* crypto-drainers) taken down 2026-07-06
On 2026-07-06 GitHub's Advisory Database published ~155 CWE-506 Embedded Malicious Code advisories against npm packages - the largest single-day 2026 GHSA npm-malware sweep to date. The batch clusters into six naming families: chalk/pino/winston/*-logger pretty-print typosquats, tailwindcss/vite typosquats, eslint / *-lint-* helper squats, bignumber.js / crypto-math typosquats, chai *-as-* matcher squats, and two polymarket-onchain-* crypto-drainer slugs continuing the June cluster. npm replaced every name with 0.0.1-security.
Versions named here: 1.0.4, 1.0.5, 1.1.0