GitHub Advisory malware sweep - 25 npm packages (Epic Games / Unreal Engine internal-scope dependency-confusion cluster, LuminaryCloud, Reddit Voyager, nodemon family) taken down 2026-07-09 / 2026-07-10
On 2026-07-09 and 2026-07-10 GitHub's Advisory Database retired 25 CWE-506 Embedded Malicious Code npm advisories. The main story is a coordinated dependency-confusion burst against internal enterprise namespaces - Epic Games / Unreal Engine build tooling (robomerge, unreal-horde-dashboard, ue-jenkins-buildkite, ue-automation-scripts, epic-internal-tools), LuminaryCloud (@luminarycloudinternal/*), Reddit-style Voyager UI (voyager-web, searchresults), plus workspace/microsite scopes - all replaced by npm Security within a 12-minute window on 2026-07-10 02:57–03:10 UTC. A smaller tail of nodemon-* / chai-redirection / paperclip-adapter-helpers typosquats and 2026-07-09 throwaways (none123s, tslint-conf) rounds out the sweep.
Versions named here: 99.9.9