GitHub Advisory malware sweep - 8 npm packages (3-package `syft-acp-*` "click2ai" dep-confusion beacon, 2-package `@edgecommons/*` preinstall-hook pair, `axios-native` + `telemetry-axios` axios typosquats, `easyway2` 12-version 4-hour burst) retired 2026-07-17 → 2026-07-18
On 2026-07-17 and 2026-07-18 GitHub's Advisory Database retired 8 CWE-506 npm malware advisories. Highlights: a 3-package syft-acp-* dependency-confusion trio published by npm account ada8877 that beacons victim IP + hostname to a Sentry ingest endpoint (byte-for-byte reuse of the earlier "click2ai" reconnaissance payload), a 2-package @edgecommons/* preinstall-hook pair, and axios typosquats axios-native + telemetry-axios.
Versions named here: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11