GitHub Advisory malware sweep - 2026-09-04/05 batch (`houdus` Windows sandbox-detection dropper + `timeweave` Windows WinExec dropper + Box internal dep-confusion via `canarytokens.com` DNS + `tailwind-contact-forms` crypto-drainer typosquat + `line-through` + `real-router-telemetry` + `claude-channel-discord` recon + amirgo4496 PyPI dep-confusion campaign)
Multi-ecosystem sweep. houdus (PyPI, Sept 5) is a Windows-only sandbox-detecting dropper; timeweave fetches Windows executables from globaltimedata.com via WinExec. Also: Box internal dep-confusion via canarytokens.com DNS, tailwind-contact-forms crypto-drainer typosquat, line-through/real-router-telemetry webhook.site exfil, and the amirgo4496 PyPI dep-confusion campaign.
Versions named here: 1.0.0, 1.1.0, 1.2.0, 1.3.0, 1.4.0, 1.5.0, 1.6.0, 1.7.0, 1.8.0, 1.9.0