GitHub Advisory malware sweep - 20 npm packages (Claude-Code / Vue-CLI "clavue" typosquat cluster, `na-rony` throwaway sextet, tailwind-core, common-tg-service six-month sleeper) taken down 2026-07-08 / 2026-07-09
On 2026-07-08 and 2026-07-09 GitHub's Advisory Database retired ~20 CWE-506 Embedded Malicious Code npm advisories, continuing the July take-down cadence at ~20 packages/day. Two distinct clusters: a clavue / Claude-Code typosquat family (myclaude-code, clavue, clavuepro, calvuepro, clavue-agent-sdk) targeting Anthropic AI CLI developers; and a *`na-rony throwaway sextet** - six packages published by one operator between 2026-07-08 03:22–03:39 UTC. Plus a tailwind-core typosquat carrying a real 4.3.x version history and the six-month sleeper common-tg-service` with 547 versions.
Versions named here: 1.2.8, 1.2.9, 1.2.10, 1.2.11, 1.2.12, 1.2.13