GitHub Advisory malware sweep - 2026-08-29 batch (npm `access-token-delta` vercel.app remote-eval cluster (3, `eth-pino` + `js-array-tokens` + `js-tokens-array`) + npm `limbomail.com` Discord-MFA Windows dropper pair (`mfacord` + `mfakit`) + npm `secretkey2fa` Minecraft/Microsoft-account stealer + npm `supersignaturenature` RSA/DES chain via `manager-thedate` + npm `techportal` HTTP+DNS beacon to `oob.asm5.net` + npm `vs-modules` Windows .bat dropper + npm `vitest-chalk-pro` jsonbin.io detached-child C2 + npm `repo.securityctrl.com` mass dependency-confusion probe (18+ enterprise namespaces: Intuit, Atlassian, Firebase, Postman, Oracle, Amplitude, Ring, Alimama, Nx, Libra…) + npm `grafeno-*` preinstall + cron persistence cluster (9 packages, 216.126.236.46/x.sh) + PyPI `calcboxlite` + `pygame-renderkit` misc + massive scripted CWE-506 bursts (`3layerdipstack*` ~100+, `classlink-*` ~100+))
Large 24h window ending 2026-08-29: the standout is a compromise of @7nohe/openapi-react-query-codegen by the "Trinitite" Mini Shai-Hulud continuation (tracked separately). Around it: three coordinated operator clusters with full IOCs (npm vercel.app remote-eval typosquats, npm limbomail.com Discord-MFA droppers, npm repo.securityctrl.com mass enterprise-namespace dependency-confusion probe), a grafeno-* cron-persistence cluster, and hundreds of scripted CWE-506 boilerplate burst-publishes (3layerdipstack*, classlink-*).
Versions named here: 1.0.5, 1.0.6