GitHub Advisory npm CWE-506 sweep - 2026-08-11 batch (webhook.site Web3 typosquat credential-theft ring `@openzeppelin-4/5/contracts`+`@aerodrome-finance/contracts`+`@aerodrome-finance/slipstream`+`ethereum-vault-connector`, `safe-local-env-loader` env-local RAT sibling, `newtun` unencrypted-WebSocket PTY RAT with self-update, `svelte-vim-kit`+`kit-vim-map` map-streak-kit family continuation, `@nzeros/codebreak` Go ELF disguised as C solver, `base65-*` base-x typosquat cluster with 123KB obfuscated payload + `bs58-*` boilerplate siblings, coordinated `oastify.com`/`sslip.io`/webhook OAST dep-confusion recon beacons)
38 npm CWE-506 advisories published 2026-08-11. Headline: five-package Web3 typosquat ring (@openzeppelin-4/contracts, @openzeppelin-5/contracts, @aerodrome-finance/contracts, @aerodrome-finance/slipstream, ethereum-vault-connector) sharing the same webhook.site credential-exfil TTP with 60-240s detached-process delay + sandbox evasion, safe-local-env-loader continuing the 2026-08-10 env-local Windows RAT, and newtun shipping a PTY reverse shell with self-update.
Versions named here: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11, 1.0.12, 1.0.13, 1.0.14, 1.0.15, 1.0.16, 1.0.17, 1.0.18, 1.0.19, 1.0.20, 1.0.21, 1.0.22, 1.0.23, 1.0.24, 1.0.25, 1.0.26, 1.0.27