Feed
HighPublished 1 Sept 2026Updated 2 Sept 202645 packages · 48 versions

GitHub Advisory malware sweep - 2026-09-01 batch (19-package `@yane88/*` Windows dev-toolchain dep-confusion probe (IntelliJ IDEA 2026.2, Listary, Reqable, ripgrep, HexHub, WorkBuddy) + PyPI `pyservercheck` Lazarus/PolinRider EtherHiding v0.1.x + `kendo-angular-window` Telerik typosquat + `fuels-*` Fuel Labs SDK 4-package typosquat + `verify-contract-*`/`generate-schema-*` EVM smart-contract-verifier 4-package cluster + `hyperliquid-composer` DeFi typosquat + `@viertechjs/*` dep-confusion 3-pack (Baileys WhatsApp / API / wb) + `react-mongoose`/`express-mongo-limit` MongoDB stack typosquats + `bamru` clipboard/screen harvester (new-pointer.vercel.app C2) + PyPI `gcphelpit` GCP-help infostealer + PyPI `tallyboxlite` recon + CWE-506 boilerplate takedowns)

Summary

19-pkg @yane88/* scope probes internal Windows dev-tool naming; PyPI pyservercheck@0.1.x is a PolinRider EtherHiding stager (.pth persistence, blockchain C2); fuels-* (4) typosquats Fuel Labs SDK; verify-contract-*/generate-schema-* (4) targets viem+ethers verifiers; bamru is a clipboard/screen harvester (C2 new-pointer.vercel.app); PyPI gcphelpit is an infostealer.

dependency-confusiontyposquatcredential-theftobfuscationinfostealercrypto-wallet-drain
Threat actor
PolinRider (Lazarus / Contagious Interview / Famous Chollima) - Cluster B only
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · Amazon Inspector
Also known as
2026-09-01 GHSA sweep · 2026-09-yane88 Windows dev-toolchain dep-confusion probe · 2026-09-pyservercheck PolinRider EtherHiding
Ecosystems
npmPyPI
Packages tracked
45

What happened

The 24 hours ending 2026-09-01 published 26 new npm+PyPI malware advisories. Headlines: a *19-package `@yane88/ scope drop** probing internal Windows dev-toolchain naming (IntelliJ IDEA 2026.2, Listary, Reqable, ripgrep-win, HexHub, WorkBuddy) with numbered -01…-06 variants signalling a dep-confusion probe; a **PyPI pyservercheck Lazarus / PolinRider EtherHiding stager** with .pth file persistence and blockchain-resolved C2; a **Telerik kendo-angular-window` typosquat**; and 5 pure CWE-506 boilerplate takedowns.

Cluster A - npm @yane88/* Windows dev-toolchain dep-confusion (19 packages)

| Package | GHSA | Note | |---|---|---| | @yane88/workbuddy | GHSA-v22h-4j6c-58cm | base WorkBuddy name | | @yane88/workbuddy-01 | GHSA-2w3r-v82c-4rvg | numbered variant | | @yane88/workbuddy-02 | GHSA-677c-x838-7qj5 | numbered variant | | @yane88/workbuddy-03 | GHSA-qpjf-29xc-g688 | numbered variant | | @yane88/listary | GHSA-6qjf-3c98-5gr7 | Listary Windows search launcher (listary.com) | | @yane88/listary-01 | GHSA-46j3-wfp2-66m2 | numbered variant | | @yane88/listary-02 | GHSA-rg2v-g672-8773 | numbered variant | | @yane88/term-reqable | GHSA-xx48-j637-66x2 | Reqable API debugger (reqable.com) | | @yane88/term-reqable-01 | GHSA-m76v-4h4c-w693 | numbered variant | | @yane88/term-reqable-02 | GHSA-vq2v-vw6h-9g9f | numbered variant | | @yane88/hexhub-client | GHSA-75h3-gh74-47p2 | hex-editor / vault-client internal | | @yane88/ripgrep-win | GHSA-274r-44qv-6xwc | Windows ripgrep binary wrapper | | @yane88/idea-2026.2 | GHSA-5qw7-3hqh-q33m | JetBrains IntelliJ IDEA 2026.2 release naming | | @yane88/idea-2026.2-01 | GHSA-2fmg-86jf-r56c | numbered variant | | @yane88/idea-2026.2-02 | GHSA-fgwh-qm8c-9mv8 | numbered variant | | @yane88/idea-2026.2-03 | GHSA-fw5q-2vvv-w862 | numbered variant | | @yane88/idea-2026.2-04 | GHSA-xpjx-pwwq-qg46 | numbered variant | | @yane88/idea-2026.2-05 | GHSA-mv54-8cx5-2fc9 | numbered variant | | @yane88/idea-2026.2-06 | GHSA-j62v-qq84-cr9v | numbered variant |

Attribution signals: (1) one scope, 19 all-versions CWE-506 takedowns published on the same day - one operator, one push; (2) package name shapes ALL track known Windows developer productivity tools; (3) the -01/-02/-03/…/-06 numbered suffixes with no version differentiation (the -01 and -02 are not 1.0.0 and 2.0.0, they are different package names) are a canonical dependency-confusion probing pattern - the operator is trying multiple internal-naming conventions in parallel expecting one variant to match a mis-scoped internal name. This is a targeted probe of an org whose internal npm scope is or resembles @yane88 and whose developers self-package Windows productivity tooling.

Cluster B - PyPI pyservercheck PolinRider EtherHiding stager

| Package | Version | GHSA | Source hash | MAL id | |---|---|---|---|---| | pyservercheck | 0.1.0 | GHSA-p6mp-76cr-jhjq | 4b365b9d…c3f760a | MAL-2026-15603 | | pyservercheck | 0.1.1 | GHSA-p6mp-76cr-jhjq | 4b365b9d…c3f760a | MAL-2026-15603 |

Payload chain: (1) install-time execution of obfuscated JS via a Python shim; (2) .pth file injected into site-packages so every future python invocation re-runs the loader; (3) second-stage payload fetched via blockchain-resolved C2 - a hardcoded ETH address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a is queried on-chain (EtherHiding technique) to resolve the current C2 URL, giving the operator resilient dead-drop infrastructure that cannot be sinkholed via DNS takedown; (4) downloaded payload matches the PolinRider / Contagious Interview / Famous Chollima DPRK Lazarus tooling seen in Beavertail / InvisibleFerret variants.

IOCs: - ETH C2 pointer address: 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a - Package repositories: pypi.org/project/pyservercheck/0.1.0, pypi.org/project/pyservercheck/0.1.1

Related tracked PolinRider activity: - litellm (2026-03-24) - telnyx (2026-03-27) - xinference (2026-04-22) - bitwarden-cli (2026-04-22) - common-stack-generate-plugin-polinrider npm cluster (2026-05-21)

Cluster C - npm kendo-angular-window Telerik/Progress typosquat

| Package | Affected versions | GHSA | |---|---|---| | kendo-angular-window | all versions (>= 0) | GHSA-jjx4-p3qc-rhrq |

All-versions CWE-506 takedown. Typosquats Telerik/Progress's legitimate @progress/kendo-angular-* UI suite (the legitimate Window component ships inside @progress/kendo-angular-dialogs). Any lockfile hit on the unscoped kendo-angular-window is a compromise; scoped @progress/kendo-angular-window should not exist.

Cluster D - npm CWE-506 boilerplate takedowns (5 packages)

| Package | Affected versions | GHSA | Note | |---|---|---|---| | matrix-by-lmx | all versions | GHSA-jhgv-vh9h-q3r9 | piggybacks Matrix protocol naming | | randomunblockedwebsite | all versions | GHSA-5x4x-f7h5-6p47 | spam / pentest probe | | core_main | all versions | GHSA-rxjr-qr5x-q4q7 | underscore naming hints at Python-project author | | quartz-core | all versions | GHSA-w63g-6crc-rq2w | typosquats @quartz/core / @quartzds/core / jackyzha0/quartz | | @fdr-mar/promos-types | all versions | GHSA-gj3w-q938-w6m6 | scope reads as dep-confusion probe of @fdr-* internal |

All are pure CWE-506 takedowns with no per-package IOCs beyond the GHSA. Defensive value is name-level: any lockfile hit means uninstall.

Registry state

All 26 packages were flagged as malware on npm / PyPI on 2026-09-01. Multiple have been yanked and replaced with holding packages by the registry security teams. Internal mirrors routinely keep serving yanked tarballs; re-sync every mirror.

Discovery credits

GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector. pyservercheck cross-referenced against bad-packages.kam193.eu/pypi/package/pyservercheck (Kamil Mańkowski's PyPI malware tracker).

Affected packages (45)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • *Cluster A - npm `@yane88/ Windows dev-toolchain dep-confusion probe (2026-09-01, 19 packages)**: @yane88/workbuddy (GHSA-v22h-4j6c-58cm), @yane88/workbuddy-01 (GHSA-2w3r-v82c-4rvg), @yane88/workbuddy-02 (GHSA-677c-x838-7qj5), @yane88/workbuddy-03 (GHSA-qpjf-29xc-g688), @yane88/listary (GHSA-6qjf-3c98-5gr7), @yane88/listary-01 (GHSA-46j3-wfp2-66m2), @yane88/listary-02 (GHSA-rg2v-g672-8773), @yane88/term-reqable (GHSA-xx48-j637-66x2), @yane88/term-reqable-01 (GHSA-m76v-4h4c-w693), @yane88/term-reqable-02 (GHSA-vq2v-vw6h-9g9f), @yane88/hexhub-client (GHSA-75h3-gh74-47p2), @yane88/ripgrep-win (GHSA-274r-44qv-6xwc), @yane88/idea-2026.2 (GHSA-5qw7-3hqh-q33m), @yane88/idea-2026.2-01 (GHSA-2fmg-86jf-r56c), @yane88/idea-2026.2-02 (GHSA-fgwh-qm8c-9mv8), @yane88/idea-2026.2-03 (GHSA-fw5q-2vvv-w862), @yane88/idea-2026.2-04 (GHSA-xpjx-pwwq-qg46), @yane88/idea-2026.2-05 (GHSA-mv54-8cx5-2fc9), @yane88/idea-2026.2-06 (GHSA-j62v-qq84-cr9v). All CWE-506 all-versions takedowns from one operator on one day. Package-name shapes track well-known Windows developer productivity tools: workbuddy (unclear internal), listary (Listary Windows search launcher, listary.com), term-reqable (Reqable API debugger, reqable.com), hexhub-client (hex-editor / vault-client internal), ripgrep-win (Windows ripgrep binary wrapper), idea-2026.2 (JetBrains IntelliJ IDEA 2026.2 release). The -01/-02/-03/…/-06 numbered suffixes are the give-away: an operator probing multiple internal-naming conventions in parallel, expecting one variant to hit an internal .npmrc scope resolver misconfigured to fall through to public npm. Any org that internally packages IntelliJ IDEA 2026.2 or the named productivity tools under an @yane88/*` scope (or any org whose CI resolves scoped packages by scope-name-only rather than full scope+registry mapping) should treat any lockfile hit as a scope-registry-misconfiguration compromise
  • Cluster B - PyPI pyservercheck Lazarus/PolinRider EtherHiding stager (2026-09-01, 1 package): pyservercheck@0.1.0 and pyservercheck@0.1.1 (GHSA-p6mp-76cr-jhjq, MAL-2026-15603, hash 4b365b9df06973db4f112bdbf2ad704dcc91c1b7b3eaceddb06a8e884c3f760a). GitHub Advisory classifies as PolinRider / Contagious Interview / Famous Chollima variant. Executes obfuscated JS-based malicious code during package install AND on every subsequent Python startup via .pth file injection (Python site-packages auto-import primitive). Downloads and executes remote second-stage payloads. Resolves command-and-control infrastructure through blockchain lookups (EtherHiding) - hardcoded ETH address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a used as a smart-contract-hosted C2 pointer. Same operator pattern as previously catalogued PolinRider entries: litellm (2026-03-24), telnyx (2026-03-27), xinference (2026-04-22), and the common-stack-generate-plugin-polinrider npm cluster (2026-05-21). Any host that ran pip install pyservercheck in the last 24 hours should be considered fully compromised; PTH-based persistence means removing the package is NOT enough - the injected .pth will keep re-executing on every Python invocation until the file is manually removed from site-packages
  • Cluster C - npm kendo-angular-window Telerik/Progress typosquat (2026-09-01, 1 package): kendo-angular-window (GHSA-jjx4-p3qc-rhrq) - all-versions CWE-506 takedown. Typosquats the legitimate @progress/kendo-angular-* scoped suite from Telerik/Progress (they publish @progress/kendo-angular-common, @progress/kendo-angular-dialogs (which houses the Window component), and dozens more scoped modules). Any Angular team using Telerik Kendo UI should audit package.json and lockfiles for the unscoped kendo-angular-window variant - it does not exist as a legitimate package and should always be uninstalled on sight
  • Cluster D - npm CWE-506 boilerplate takedowns (2026-09-01, 5 packages, no per-package IOCs): matrix-by-lmx (GHSA-jhgv-vh9h-q3r9) - piggybacks Matrix communication protocol naming; randomunblockedwebsite (GHSA-5x4x-f7h5-6p47) - reads as spam/pentest probe; core_main (GHSA-rxjr-qr5x-q4q7) - underscore-in-name is unusual for npm and hints at a Python-project author dropping onto the wrong registry (still malware per advisory); quartz-core (GHSA-w63g-6crc-rq2w) - typosquats the @quartz/core, @quartzds/core, and quartz-js/core design-system scopes as well as the popular jackyzha0/quartz static-site generator; @fdr-mar/promos-types (GHSA-gj3w-q938-w6m6) - scope-name @fdr-mar reads as a dependency-confusion probe of an internal "promos-types" package (any org shipping under an @fdr-* scope should audit registry mappings). All-versions takedowns with no per-package IOCs beyond the GHSA takedown itself - defensive value is name-level: any lockfile hit means uninstall
  • *Cluster E - npm `fuels- Fuel Labs SDK typosquat (2026-09-01, 4 packages, added 2026-09-02 refresh)**: fuels-core (GHSA-82rr-x2r8-gjhm), fuels-forc (GHSA-h4w6-844f-2fxw), fuels-typegen (GHSA-c4wf-579x-f397), fuels-versions (GHSA-7478-v9hq-9835 / GHSA-cxcx-864c-x6vp - double disclosure). All all-versions CWE-506 takedowns. Typosquats the legitimate fuels TS SDK from Fuel Labs (the modular Rust/TypeScript blockchain that ships tools named forc (Fuel Orchestrator), fuels-ts (SDK), typegen, and versions under the fuels- npm scope, PLUS the @fuel-ts/ scoped variant). Any dApp or Sway smart-contract team should confirm their lockfile pulls the legitimate fuels/@fuel-ts/* package family and not the drop-in-lookalike fuels-core/fuels-forc/fuels-typegen/fuels-versions` unscoped names
  • Cluster F - npm EVM smart-contract-verifier typosquat cluster (2026-09-01, 5 packages, added 2026-09-02 refresh): verify-contract-viem (GHSA-rhm2-cc4p-vfxq), verify-contract-ethers (GHSA-cvw4-2h4c-hm3f), generate-schema-viem (GHSA-72cf-ghpg-mj8h), generate-schema-ethers (GHSA-3c7v-grhq-3m56), hyperliquid-composer (GHSA-5v7v-27c5-fr8q). All all-versions CWE-506 takedowns. The verify-contract-* / generate-schema-* twin-suffix pattern (-viem and -ethers are the two dominant EVM JS client libraries) is a deliberate net cast at any Solidity / EVM developer who guesses at a verification helper package name. Once installed at RCE the operator sits inside a contract-deployment or ABI-generation pipeline - the ideal position for silently rewriting a contract-verification submission (sourcify.eth / etherscan API calls) to hide backdoored bytecode. hyperliquid-composer extends the same operator into Hyperliquid DEX tooling
  • *Cluster G - npm `@viertechjs/ dep-confusion probe (2026-09-01, 3 packages, added 2026-09-02 refresh)**: @viertechjs/wb (GHSA-3f73-cx58-g87j), @viertechjs/baileys (GHSA-wcqj-8x6x-4pxr), @viertechjs/api (GHSA-62qr-2m9g-fm38). All all-versions CWE-506 takedowns. The @viertechjs scope is a fresh throwaway (no legitimate publisher), and the three sub-names are a canonical dep-confusion probe shape: api (generic internal REST client), baileys (the legitimate @whiskeysockets/baileys unofficial WhatsApp Web API is a common Node.js internal dependency for chatbot / notification pipelines), wb (whiteboard / WhatsApp-bot / WebSocket internal). Any org shipping an @viertech*` scope or a Baileys-based WhatsApp integration should audit registry-scope mappings
  • Cluster H - npm MongoDB stack typosquat pair (2026-09-01, 2 packages, added 2026-09-02 refresh): react-mongoose (GHSA-wvgj-m2p9-jf3c) and express-mongo-limit (GHSA-rw8f-rf6x-jj3j). All all-versions CWE-506 takedowns. mongoose is not a React library (it is a Node.js server-side ODM), so react-mongoose is a pure trap for developers guessing at a "React wrapper for Mongoose". express-mongo-limit reads as a rate-limit / MongoDB middleware helper. Any Node/Express + MongoDB stack that pulled either should assume RCE at install
  • Cluster I - npm bamru clipboard/screen harvester with named C2 (2026-09-01, 1 package, added 2026-09-02 refresh): bamru (GHSA-jr4p-f775-3jjp) all-versions CWE-506. Only advisory in the batch with a named IOC: exfiltration endpoint https://new-pointer.vercel.app/api. Package masquerades as a system configuration tool while installing credential-stealing capabilities. Runtime behaviours: reads the clipboard on a periodic timer, captures screen contents via UI automation, transmits captured data to the Vercel-hosted callback. Operates with administrative elevation and hidden windows to evade user detection. Any host that installed bamru should be treated as having leaked clipboard-copied secrets (passwords, private keys, MFA seeds) for the entire exposure window
  • Cluster J - npm CWE-506 boilerplate additions (2026-09-01, 3 packages, added 2026-09-02 refresh): npx-oob-package (GHSA-95gx-59fv-gfg6) - npx-oob-* naming is the classic Out-Of-Band DNS-callback pentest probe shape; cre-setup (GHSA-4894-fvv8-2p2j) - short generic name matches internal-tool dep-confusion probe; matrix-by-lmx and siblings unchanged. All all-versions CWE-506 takedowns with no per-package IOCs
  • Cluster K - PyPI additions (2026-09-01, 2 packages, added 2026-09-02 refresh): gcphelpit@0.1.0, 0.1.1, 0.1.2 (GHSA-9jm3-2h34-h9g3, campaign 2026-09-gcphelpit) - "GCP help it" naming targets Google Cloud Platform helper / support tooling, positioning to catch cloud-ops installs; 0.1.0/0.1.1 shipped PoC calculator-launcher stubs but 0.1.2 actively exfiltrates sensitive files during CLI initialization (infostealer graduation). tallyboxlite@1.0 (GHSA-x92w-4wvc-qx2w, campaign GENERIC-standard-pypi-install-pentest) - classified PROBABLY_PENTEST by OpenSSF, overrides setup.py install to run at install-time and exfiltrates host reconnaissance (IP, username). Neither has been retracted by the operator; both remain in the mirror deny-list until formally yanked

What to do

  1. 1Grep every lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt, Pipfile.lock, poetry.lock, uv.lock) for: @yane88/workbuddy, @yane88/workbuddy-01, @yane88/workbuddy-02, @yane88/workbuddy-03, @yane88/listary, @yane88/listary-01, @yane88/listary-02, @yane88/term-reqable, @yane88/term-reqable-01, @yane88/term-reqable-02, @yane88/hexhub-client, @yane88/ripgrep-win, @yane88/idea-2026.2, @yane88/idea-2026.2-01, @yane88/idea-2026.2-02, @yane88/idea-2026.2-03, @yane88/idea-2026.2-04, @yane88/idea-2026.2-05, @yane88/idea-2026.2-06, pyservercheck, kendo-angular-window, matrix-by-lmx, randomunblockedwebsite, core_main, quartz-core, @fdr-mar/promos-types, fuels-core, fuels-forc, fuels-typegen, fuels-versions, verify-contract-viem, verify-contract-ethers, generate-schema-viem, generate-schema-ethers, hyperliquid-composer, @viertechjs/wb, @viertechjs/baileys, @viertechjs/api, react-mongoose, express-mongo-limit, bamru, npx-oob-package, cre-setup, gcphelpit, tallyboxlite. Uninstall on any hit and rebuild the lockfile against a clean cache
  2. 2*For Cluster A (`@yane88/ Windows dev-toolchain dep-confusion)**: any org that internally packages IntelliJ IDEA 2026.2 (or older IDEA releases), Listary, Reqable, HexHub, or a ripgrep Windows binary under an @yane88/ scope MUST audit .npmrc scope-registry mappings. Ensure any @yane88:registry= entry points to your internal registry, always-auth = true, and that no CI job falls through to public npm for that scope. Version-pin every internal @yane88/ dependency. Review developer workstation ~/.npm/_logs for any recent install @yane88/*` line. Rotate any GitHub PAT / npm token / IDE license key that touched an affected workstation - the operator may already have IDE-configuration exfiltration
  3. 3For Cluster B (pyservercheck PolinRider EtherHiding): on any host that pip install pyservercheck (or that pulled it transitively), consider it fully compromised. Do NOT rely on pip uninstall pyservercheck alone: the malicious .pth file injected into site-packages will keep re-running on every python/python3 invocation. Manually grep site-packages for the injected .pth and delete it; then rotate every credential accessible on the host - SSH keys, cloud metadata tokens (AWS/GCP/Azure), Vault, GitHub PATs, npm/pypi/rubygems tokens, browser session cookies, keychain entries. Watch outbound DNS/TCP for lookups against Ethereum RPC endpoints and JSON-RPC calls to the C2 contract at 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a. This is a DPRK/Lazarus North Korea IT-worker campaign - if this landed inside a corporate perimeter, expect follow-on account takeover, code-repo access, and (in the worst case) coordinated fraudulent-remote-worker enrolment
  4. 4For Cluster C (kendo-angular-window): confirm every Kendo UI dependency in package.json is a scoped @progress/kendo-angular-* package, NOT the unscoped kendo-angular-window. The legitimate Window component lives in @progress/kendo-angular-dialogs. If your build tooling has ever auto-installed kendo-angular-window, uninstall and audit downstream Angular apps for any injected postinstall/JS payload
  5. 5For Cluster D (CWE-506 boilerplate takedowns): any lockfile hit means uninstall and rebuild; the advisory-level guidance is "consider the machine fully compromised, rotate secrets, do not assume removal is sufficient". Special attention for @fdr-mar/promos-types: if your org uses an @fdr-* scope internally, treat it as a dependency-confusion probe and audit scope-registry routing per Cluster A guidance
  6. 6*For Cluster E (`fuels- Fuel Labs SDK typosquat)**: any dApp / Sway / Fuel Rust-VM team should confirm every fuels-family install resolves to the legitimate fuels package or @fuel-ts/* scope. Never install fuels-core, fuels-forc, fuels-typegen, or fuels-versions` as unscoped packages - they are all malware. Rotate any wallet seed / RPC credential that touched a machine which pulled one
  7. 7For Cluster F (EVM smart-contract-verifier typosquat cluster): any repo that submits contract verification to sourcify.eth, Etherscan, Blockscout, or a chain-specific verifier from a CI job that installed verify-contract-viem, verify-contract-ethers, generate-schema-viem, generate-schema-ethers, or hyperliquid-composer must assume its most recent verification submissions may have been silently rewritten to hide backdoored bytecode. Re-verify affected contracts from a clean CI runner, and audit for any recently-deployed contract where the on-chain bytecode disagrees with your source-of-truth build
  8. 8*For Cluster G (`@viertechjs/ dep-confusion probe)**: audit .npmrc for any @viertech* scope resolver; ensure it routes to your internal registry with always-auth = true. Baileys-based WhatsApp integrations should verify the dependency is @whiskeysockets/baileys, NOT @viertechjs/baileys`
  9. 9For Cluster H (Mongo stack typosquats): mongoose is a Node.js server-side ODM - a "React wrapper for Mongoose" does not exist. Any package.json line with react-mongoose should be deleted. express-mongo-limit should be replaced with the legitimate express-rate-limit + rate-limit-mongo pair
  10. 10For Cluster I (bamru clipboard/screen harvester): on any host that installed bamru, block outbound traffic to new-pointer.vercel.app and grep proxy / firewall logs for prior connections to that domain. Rotate every credential that may have been in the clipboard during the exposure window: passwords, private keys, MFA seed backups, wallet mnemonics, cloud CLI tokens. Screen captures are also exfiltrated - if the affected host displayed sensitive documents on screen (contracts, PII, source code, dashboards), treat that content as leaked
  11. 11For Cluster K (PyPI gcphelpit / tallyboxlite): on any host that ran pip install gcphelpit (especially 0.1.2 or later), assume all local files accessible to the invoking user have been exfiltrated - rotate GCP service account keys, gcloud cached credentials, and any secret file in the user's home directory. tallyboxlite is lower-severity host reconnaissance but still ran arbitrary code at install: same uninstall-and-rebuild guidance
  12. 12For all npm install runs in CI, prefer --ignore-scripts - dep-confusion pkgs still typically ship postinstall/preinstall hooks
  13. 13For all pip install runs in CI, prefer --no-build-isolation + explicit --only-binary where possible. Note: pyservercheck's .pth injection primitive is triggered by ANY install path, not just source builds, so --only-binary alone is not sufficient - add pyservercheck (and any variant) to your registry-mirror deny list
  14. 14Verify none of the enumerated packages still resolves via your private mirror - internal caches (Nexus / Artifactory / Verdaccio / Sonatype / devpi) routinely keep serving yanked tarballs after the public takedown

References

multi-2026-09-01-ghsa-malware-sweep