GitHub Advisory malware sweep - 2026-08-28 batch (PyPI `flyteplugins-*` dependency-confusion cluster (4) + PyPI `discordnv` Discord/Roblox DPAPI infostealer + PyPI `decoris` Roblox cookie stealer + PyPI `sap-quarterly-report` + `ekx-report-utils` DNS-exfil pair + PyPI `mathkitlite` PROBABLY_PENTEST + npm `@postman-cse/okta-aio-darwin-arm64` internal-namespace dependency-confusion probe + npm `@hd-team/*` cluster (8) + npm `hydration-ui-dlx` / `svelte-ui-dlx` hydration-lookalike continuation + npm `tailwindcss-*` typosquats (2) + npm long-tail CWE-506 boilerplate)
31 new GHSA malware advisories in the 24h window ending 2026-08-28. Highlights: 4 flyteplugins-* PyPI packages all published at the identical exact version 2.6.10 - a dependency-confusion probe against Union.ai / Flyte internal package namespaces; PyPI discordnv@0.8.0 steals Discord tokens plus DPAPI-decrypts Roblox cookies with full Discord-webhook + Google-Apps-Script + registry-persistence IOCs; PyPI sap-quarterly-report + ekx-report-utils share a DNS-exfil campaign; npm @postman-cse/okta-aio-darwin-arm64 reads as a Postman internal okta-aio binary namespace hit.
Versions named here: 1.0.0, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11, 1.0.12, 1.0.13, 1.0.14, 1.0.15, 1.0.16, 1.0.17