GitHub Advisory malware sweep - 2026-09-01 batch (19-package `@yane88/*` Windows dev-toolchain dep-confusion probe (IntelliJ IDEA 2026.2, Listary, Reqable, ripgrep, HexHub, WorkBuddy) + PyPI `pyservercheck` Lazarus/PolinRider EtherHiding v0.1.x + `kendo-angular-window` Telerik typosquat + `fuels-*` Fuel Labs SDK 4-package typosquat + `verify-contract-*`/`generate-schema-*` EVM smart-contract-verifier 4-package cluster + `hyperliquid-composer` DeFi typosquat + `@viertechjs/*` dep-confusion 3-pack (Baileys WhatsApp / API / wb) + `react-mongoose`/`express-mongo-limit` MongoDB stack typosquats + `bamru` clipboard/screen harvester (new-pointer.vercel.app C2) + PyPI `gcphelpit` GCP-help infostealer + PyPI `tallyboxlite` recon + CWE-506 boilerplate takedowns)
19-pkg @yane88/* scope probes internal Windows dev-tool naming; PyPI pyservercheck@0.1.x is a PolinRider EtherHiding stager (.pth persistence, blockchain C2); fuels-* (4) typosquats Fuel Labs SDK; verify-contract-*/generate-schema-* (4) targets viem+ethers verifiers; bamru is a clipboard/screen harvester (C2 new-pointer.vercel.app); PyPI gcphelpit is an infostealer.
- Threat actor
- PolinRider (Lazarus / Contagious Interview / Famous Chollima) - Cluster B only
- Detected by
- GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · Amazon Inspector
- Also known as
- 2026-09-01 GHSA sweep · 2026-09-yane88 Windows dev-toolchain dep-confusion probe · 2026-09-pyservercheck PolinRider EtherHiding
- Ecosystems
- npmPyPI
- Packages tracked
- 45
What happened
The 24 hours ending 2026-09-01 published 26 new npm+PyPI malware advisories. Headlines: a *19-package `@yane88/ scope drop** probing internal Windows dev-toolchain naming (IntelliJ IDEA 2026.2, Listary, Reqable, ripgrep-win, HexHub, WorkBuddy) with numbered -01…-06 variants signalling a dep-confusion probe; a **PyPI pyservercheck Lazarus / PolinRider EtherHiding stager** with .pth file persistence and blockchain-resolved C2; a **Telerik kendo-angular-window` typosquat**; and 5 pure CWE-506 boilerplate takedowns.
Cluster A - npm @yane88/* Windows dev-toolchain dep-confusion (19 packages)
| Package | GHSA | Note | |---|---|---| | @yane88/workbuddy | GHSA-v22h-4j6c-58cm | base WorkBuddy name | | @yane88/workbuddy-01 | GHSA-2w3r-v82c-4rvg | numbered variant | | @yane88/workbuddy-02 | GHSA-677c-x838-7qj5 | numbered variant | | @yane88/workbuddy-03 | GHSA-qpjf-29xc-g688 | numbered variant | | @yane88/listary | GHSA-6qjf-3c98-5gr7 | Listary Windows search launcher (listary.com) | | @yane88/listary-01 | GHSA-46j3-wfp2-66m2 | numbered variant | | @yane88/listary-02 | GHSA-rg2v-g672-8773 | numbered variant | | @yane88/term-reqable | GHSA-xx48-j637-66x2 | Reqable API debugger (reqable.com) | | @yane88/term-reqable-01 | GHSA-m76v-4h4c-w693 | numbered variant | | @yane88/term-reqable-02 | GHSA-vq2v-vw6h-9g9f | numbered variant | | @yane88/hexhub-client | GHSA-75h3-gh74-47p2 | hex-editor / vault-client internal | | @yane88/ripgrep-win | GHSA-274r-44qv-6xwc | Windows ripgrep binary wrapper | | @yane88/idea-2026.2 | GHSA-5qw7-3hqh-q33m | JetBrains IntelliJ IDEA 2026.2 release naming | | @yane88/idea-2026.2-01 | GHSA-2fmg-86jf-r56c | numbered variant | | @yane88/idea-2026.2-02 | GHSA-fgwh-qm8c-9mv8 | numbered variant | | @yane88/idea-2026.2-03 | GHSA-fw5q-2vvv-w862 | numbered variant | | @yane88/idea-2026.2-04 | GHSA-xpjx-pwwq-qg46 | numbered variant | | @yane88/idea-2026.2-05 | GHSA-mv54-8cx5-2fc9 | numbered variant | | @yane88/idea-2026.2-06 | GHSA-j62v-qq84-cr9v | numbered variant |
Attribution signals: (1) one scope, 19 all-versions CWE-506 takedowns published on the same day - one operator, one push; (2) package name shapes ALL track known Windows developer productivity tools; (3) the -01/-02/-03/…/-06 numbered suffixes with no version differentiation (the -01 and -02 are not 1.0.0 and 2.0.0, they are different package names) are a canonical dependency-confusion probing pattern - the operator is trying multiple internal-naming conventions in parallel expecting one variant to match a mis-scoped internal name. This is a targeted probe of an org whose internal npm scope is or resembles @yane88 and whose developers self-package Windows productivity tooling.
Cluster B - PyPI pyservercheck PolinRider EtherHiding stager
| Package | Version | GHSA | Source hash | MAL id | |---|---|---|---|---| | pyservercheck | 0.1.0 | GHSA-p6mp-76cr-jhjq | 4b365b9d…c3f760a | MAL-2026-15603 | | pyservercheck | 0.1.1 | GHSA-p6mp-76cr-jhjq | 4b365b9d…c3f760a | MAL-2026-15603 |
Payload chain: (1) install-time execution of obfuscated JS via a Python shim; (2) .pth file injected into site-packages so every future python invocation re-runs the loader; (3) second-stage payload fetched via blockchain-resolved C2 - a hardcoded ETH address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a is queried on-chain (EtherHiding technique) to resolve the current C2 URL, giving the operator resilient dead-drop infrastructure that cannot be sinkholed via DNS takedown; (4) downloaded payload matches the PolinRider / Contagious Interview / Famous Chollima DPRK Lazarus tooling seen in Beavertail / InvisibleFerret variants.
IOCs: - ETH C2 pointer address: 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a - Package repositories: pypi.org/project/pyservercheck/0.1.0, pypi.org/project/pyservercheck/0.1.1
Related tracked PolinRider activity: - litellm (2026-03-24) - telnyx (2026-03-27) - xinference (2026-04-22) - bitwarden-cli (2026-04-22) - common-stack-generate-plugin-polinrider npm cluster (2026-05-21)
Cluster C - npm kendo-angular-window Telerik/Progress typosquat
| Package | Affected versions | GHSA | |---|---|---| | kendo-angular-window | all versions (>= 0) | GHSA-jjx4-p3qc-rhrq |
All-versions CWE-506 takedown. Typosquats Telerik/Progress's legitimate @progress/kendo-angular-* UI suite (the legitimate Window component ships inside @progress/kendo-angular-dialogs). Any lockfile hit on the unscoped kendo-angular-window is a compromise; scoped @progress/kendo-angular-window should not exist.
Cluster D - npm CWE-506 boilerplate takedowns (5 packages)
| Package | Affected versions | GHSA | Note | |---|---|---|---| | matrix-by-lmx | all versions | GHSA-jhgv-vh9h-q3r9 | piggybacks Matrix protocol naming | | randomunblockedwebsite | all versions | GHSA-5x4x-f7h5-6p47 | spam / pentest probe | | core_main | all versions | GHSA-rxjr-qr5x-q4q7 | underscore naming hints at Python-project author | | quartz-core | all versions | GHSA-w63g-6crc-rq2w | typosquats @quartz/core / @quartzds/core / jackyzha0/quartz | | @fdr-mar/promos-types | all versions | GHSA-gj3w-q938-w6m6 | scope reads as dep-confusion probe of @fdr-* internal |
All are pure CWE-506 takedowns with no per-package IOCs beyond the GHSA. Defensive value is name-level: any lockfile hit means uninstall.
Registry state
All 26 packages were flagged as malware on npm / PyPI on 2026-09-01. Multiple have been yanked and replaced with holding packages by the registry security teams. Internal mirrors routinely keep serving yanked tarballs; re-sync every mirror.
Discovery credits
GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector. pyservercheck cross-referenced against bad-packages.kam193.eu/pypi/package/pyservercheck (Kamil Mańkowski's PyPI malware tracker).
Affected packages (45)
- npm@fdr-mar/promos-types0.0.0
- npm@viertechjs/api0.0.0
- npm@viertechjs/baileys0.0.0
- npm@viertechjs/wb0.0.0
- npm@yane88/hexhub-client0.0.0
- npm@yane88/idea-2026.20.0.0
- npm@yane88/idea-2026.2-010.0.0
- npm@yane88/idea-2026.2-020.0.0
- npm@yane88/idea-2026.2-030.0.0
- npm@yane88/idea-2026.2-040.0.0
- npm@yane88/idea-2026.2-050.0.0
- npm@yane88/idea-2026.2-060.0.0
- npm@yane88/listary0.0.0
- npm@yane88/listary-010.0.0
- npm@yane88/listary-020.0.0
- npm@yane88/ripgrep-win0.0.0
- npm@yane88/term-reqable0.0.0
- npm@yane88/term-reqable-010.0.0
- npm@yane88/term-reqable-020.0.0
- npm@yane88/workbuddy0.0.0
- npm@yane88/workbuddy-010.0.0
- npm@yane88/workbuddy-020.0.0
- npm@yane88/workbuddy-030.0.0
- npmbamru0.0.0
- npmcore_main0.0.0
- npmcre-setup0.0.0
- npmexpress-mongo-limit0.0.0
- npmfuels-core0.0.0
- npmfuels-forc0.0.0
- npmfuels-typegen0.0.0
- npmfuels-versions0.0.0
- PyPIgcphelpit0.1.00.1.10.1.2
- npmgenerate-schema-ethers0.0.0
- npmgenerate-schema-viem0.0.0
- npmhyperliquid-composer0.0.0
- npmkendo-angular-window0.0.0
- npmmatrix-by-lmx0.0.0
- npmnpx-oob-package0.0.0
- PyPIpyservercheck0.1.00.1.1
- npmquartz-core0.0.0
- npmrandomunblockedwebsite0.0.0
- npmreact-mongoose0.0.0
- PyPItallyboxlite1.0
- npmverify-contract-ethers0.0.0
- npmverify-contract-viem0.0.0
These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.
Impact
- *Cluster A - npm `@yane88/
Windows dev-toolchain dep-confusion probe (2026-09-01, 19 packages)**:@yane88/workbuddy(GHSA-v22h-4j6c-58cm),@yane88/workbuddy-01(GHSA-2w3r-v82c-4rvg),@yane88/workbuddy-02(GHSA-677c-x838-7qj5),@yane88/workbuddy-03(GHSA-qpjf-29xc-g688),@yane88/listary(GHSA-6qjf-3c98-5gr7),@yane88/listary-01(GHSA-46j3-wfp2-66m2),@yane88/listary-02(GHSA-rg2v-g672-8773),@yane88/term-reqable(GHSA-xx48-j637-66x2),@yane88/term-reqable-01(GHSA-m76v-4h4c-w693),@yane88/term-reqable-02(GHSA-vq2v-vw6h-9g9f),@yane88/hexhub-client(GHSA-75h3-gh74-47p2),@yane88/ripgrep-win(GHSA-274r-44qv-6xwc),@yane88/idea-2026.2(GHSA-5qw7-3hqh-q33m),@yane88/idea-2026.2-01(GHSA-2fmg-86jf-r56c),@yane88/idea-2026.2-02(GHSA-fgwh-qm8c-9mv8),@yane88/idea-2026.2-03(GHSA-fw5q-2vvv-w862),@yane88/idea-2026.2-04(GHSA-xpjx-pwwq-qg46),@yane88/idea-2026.2-05(GHSA-mv54-8cx5-2fc9),@yane88/idea-2026.2-06(GHSA-j62v-qq84-cr9v). All CWE-506 all-versions takedowns from one operator on one day. Package-name shapes track well-known Windows developer productivity tools:workbuddy(unclear internal),listary(Listary Windows search launcher, listary.com),term-reqable(Reqable API debugger, reqable.com),hexhub-client(hex-editor / vault-client internal),ripgrep-win(Windows ripgrep binary wrapper),idea-2026.2(JetBrains IntelliJ IDEA 2026.2 release). The-01/-02/-03/…/-06numbered suffixes are the give-away: an operator probing multiple internal-naming conventions in parallel, expecting one variant to hit an internal.npmrcscope resolver misconfigured to fall through to public npm. Any org that internally packages IntelliJ IDEA 2026.2 or the named productivity tools under an@yane88/*` scope (or any org whose CI resolves scoped packages by scope-name-only rather than full scope+registry mapping) should treat any lockfile hit as a scope-registry-misconfiguration compromise - Cluster B - PyPI
pyservercheckLazarus/PolinRider EtherHiding stager (2026-09-01, 1 package):pyservercheck@0.1.0andpyservercheck@0.1.1(GHSA-p6mp-76cr-jhjq, MAL-2026-15603, hash4b365b9df06973db4f112bdbf2ad704dcc91c1b7b3eaceddb06a8e884c3f760a). GitHub Advisory classifies asPolinRider / Contagious Interview / Famous Chollimavariant. Executes obfuscated JS-based malicious code during package install AND on every subsequent Python startup via.pthfile injection (Python site-packages auto-import primitive). Downloads and executes remote second-stage payloads. Resolves command-and-control infrastructure through blockchain lookups (EtherHiding) - hardcoded ETH address0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1aused as a smart-contract-hosted C2 pointer. Same operator pattern as previously catalogued PolinRider entries:litellm(2026-03-24),telnyx(2026-03-27),xinference(2026-04-22), and thecommon-stack-generate-plugin-polinridernpm cluster (2026-05-21). Any host that ranpip install pyservercheckin the last 24 hours should be considered fully compromised; PTH-based persistence means removing the package is NOT enough - the injected.pthwill keep re-executing on every Python invocation until the file is manually removed fromsite-packages - Cluster C - npm
kendo-angular-windowTelerik/Progress typosquat (2026-09-01, 1 package):kendo-angular-window(GHSA-jjx4-p3qc-rhrq) - all-versions CWE-506 takedown. Typosquats the legitimate@progress/kendo-angular-*scoped suite from Telerik/Progress (they publish@progress/kendo-angular-common,@progress/kendo-angular-dialogs(which houses theWindowcomponent), and dozens more scoped modules). Any Angular team using Telerik Kendo UI should auditpackage.jsonand lockfiles for the unscopedkendo-angular-windowvariant - it does not exist as a legitimate package and should always be uninstalled on sight - Cluster D - npm CWE-506 boilerplate takedowns (2026-09-01, 5 packages, no per-package IOCs):
matrix-by-lmx(GHSA-jhgv-vh9h-q3r9) - piggybacks Matrix communication protocol naming;randomunblockedwebsite(GHSA-5x4x-f7h5-6p47) - reads as spam/pentest probe;core_main(GHSA-rxjr-qr5x-q4q7) - underscore-in-name is unusual for npm and hints at a Python-project author dropping onto the wrong registry (still malware per advisory);quartz-core(GHSA-w63g-6crc-rq2w) - typosquats the@quartz/core,@quartzds/core, andquartz-js/coredesign-system scopes as well as the popularjackyzha0/quartzstatic-site generator;@fdr-mar/promos-types(GHSA-gj3w-q938-w6m6) - scope-name@fdr-marreads as a dependency-confusion probe of an internal "promos-types" package (any org shipping under an@fdr-*scope should audit registry mappings). All-versions takedowns with no per-package IOCs beyond the GHSA takedown itself - defensive value is name-level: any lockfile hit means uninstall - *Cluster E - npm `fuels-
Fuel Labs SDK typosquat (2026-09-01, 4 packages, added 2026-09-02 refresh)**:fuels-core(GHSA-82rr-x2r8-gjhm),fuels-forc(GHSA-h4w6-844f-2fxw),fuels-typegen(GHSA-c4wf-579x-f397),fuels-versions(GHSA-7478-v9hq-9835 / GHSA-cxcx-864c-x6vp - double disclosure). All all-versions CWE-506 takedowns. Typosquats the legitimatefuelsTS SDK from Fuel Labs (the modular Rust/TypeScript blockchain that ships tools namedforc(Fuel Orchestrator),fuels-ts(SDK),typegen, andversionsunder thefuels-npm scope, PLUS the@fuel-ts/scoped variant). Any dApp or Sway smart-contract team should confirm their lockfile pulls the legitimatefuels/@fuel-ts/*package family and not the drop-in-lookalikefuels-core/fuels-forc/fuels-typegen/fuels-versions` unscoped names - Cluster F - npm EVM smart-contract-verifier typosquat cluster (2026-09-01, 5 packages, added 2026-09-02 refresh):
verify-contract-viem(GHSA-rhm2-cc4p-vfxq),verify-contract-ethers(GHSA-cvw4-2h4c-hm3f),generate-schema-viem(GHSA-72cf-ghpg-mj8h),generate-schema-ethers(GHSA-3c7v-grhq-3m56),hyperliquid-composer(GHSA-5v7v-27c5-fr8q). All all-versions CWE-506 takedowns. Theverify-contract-*/generate-schema-*twin-suffix pattern (-viemand-ethersare the two dominant EVM JS client libraries) is a deliberate net cast at any Solidity / EVM developer who guesses at a verification helper package name. Once installed at RCE the operator sits inside a contract-deployment or ABI-generation pipeline - the ideal position for silently rewriting a contract-verification submission (sourcify.eth/etherscanAPI calls) to hide backdoored bytecode.hyperliquid-composerextends the same operator into Hyperliquid DEX tooling - *Cluster G - npm `@viertechjs/
dep-confusion probe (2026-09-01, 3 packages, added 2026-09-02 refresh)**:@viertechjs/wb(GHSA-3f73-cx58-g87j),@viertechjs/baileys(GHSA-wcqj-8x6x-4pxr),@viertechjs/api(GHSA-62qr-2m9g-fm38). All all-versions CWE-506 takedowns. The@viertechjsscope is a fresh throwaway (no legitimate publisher), and the three sub-names are a canonical dep-confusion probe shape:api(generic internal REST client),baileys(the legitimate@whiskeysockets/baileysunofficial WhatsApp Web API is a common Node.js internal dependency for chatbot / notification pipelines),wb(whiteboard / WhatsApp-bot / WebSocket internal). Any org shipping an@viertech*` scope or a Baileys-based WhatsApp integration should audit registry-scope mappings - Cluster H - npm MongoDB stack typosquat pair (2026-09-01, 2 packages, added 2026-09-02 refresh):
react-mongoose(GHSA-wvgj-m2p9-jf3c) andexpress-mongo-limit(GHSA-rw8f-rf6x-jj3j). All all-versions CWE-506 takedowns.mongooseis not a React library (it is a Node.js server-side ODM), soreact-mongooseis a pure trap for developers guessing at a "React wrapper for Mongoose".express-mongo-limitreads as a rate-limit / MongoDB middleware helper. Any Node/Express + MongoDB stack that pulled either should assume RCE at install - Cluster I - npm
bamruclipboard/screen harvester with named C2 (2026-09-01, 1 package, added 2026-09-02 refresh):bamru(GHSA-jr4p-f775-3jjp) all-versions CWE-506. Only advisory in the batch with a named IOC: exfiltration endpointhttps://new-pointer.vercel.app/api. Package masquerades as a system configuration tool while installing credential-stealing capabilities. Runtime behaviours: reads the clipboard on a periodic timer, captures screen contents via UI automation, transmits captured data to the Vercel-hosted callback. Operates with administrative elevation and hidden windows to evade user detection. Any host that installedbamrushould be treated as having leaked clipboard-copied secrets (passwords, private keys, MFA seeds) for the entire exposure window - Cluster J - npm CWE-506 boilerplate additions (2026-09-01, 3 packages, added 2026-09-02 refresh):
npx-oob-package(GHSA-95gx-59fv-gfg6) -npx-oob-*naming is the classic Out-Of-Band DNS-callback pentest probe shape;cre-setup(GHSA-4894-fvv8-2p2j) - short generic name matches internal-tool dep-confusion probe;matrix-by-lmxand siblings unchanged. All all-versions CWE-506 takedowns with no per-package IOCs - Cluster K - PyPI additions (2026-09-01, 2 packages, added 2026-09-02 refresh):
gcphelpit@0.1.0, 0.1.1, 0.1.2(GHSA-9jm3-2h34-h9g3, campaign2026-09-gcphelpit) - "GCP help it" naming targets Google Cloud Platform helper / support tooling, positioning to catch cloud-ops installs;0.1.0/0.1.1shipped PoC calculator-launcher stubs but0.1.2actively exfiltrates sensitive files during CLI initialization (infostealer graduation).tallyboxlite@1.0(GHSA-x92w-4wvc-qx2w, campaignGENERIC-standard-pypi-install-pentest) - classifiedPROBABLY_PENTESTby OpenSSF, overridessetup.py installto run at install-time and exfiltrates host reconnaissance (IP, username). Neither has been retracted by the operator; both remain in the mirror deny-list until formally yanked
What to do
- 1Grep every lockfile (
package-lock.json,yarn.lock,pnpm-lock.yaml,requirements.txt,Pipfile.lock,poetry.lock,uv.lock) for:@yane88/workbuddy,@yane88/workbuddy-01,@yane88/workbuddy-02,@yane88/workbuddy-03,@yane88/listary,@yane88/listary-01,@yane88/listary-02,@yane88/term-reqable,@yane88/term-reqable-01,@yane88/term-reqable-02,@yane88/hexhub-client,@yane88/ripgrep-win,@yane88/idea-2026.2,@yane88/idea-2026.2-01,@yane88/idea-2026.2-02,@yane88/idea-2026.2-03,@yane88/idea-2026.2-04,@yane88/idea-2026.2-05,@yane88/idea-2026.2-06,pyservercheck,kendo-angular-window,matrix-by-lmx,randomunblockedwebsite,core_main,quartz-core,@fdr-mar/promos-types,fuels-core,fuels-forc,fuels-typegen,fuels-versions,verify-contract-viem,verify-contract-ethers,generate-schema-viem,generate-schema-ethers,hyperliquid-composer,@viertechjs/wb,@viertechjs/baileys,@viertechjs/api,react-mongoose,express-mongo-limit,bamru,npx-oob-package,cre-setup,gcphelpit,tallyboxlite. Uninstall on any hit and rebuild the lockfile against a clean cache - 2*For Cluster A (`@yane88/
Windows dev-toolchain dep-confusion)**: any org that internally packages IntelliJ IDEA 2026.2 (or older IDEA releases), Listary, Reqable, HexHub, or aripgrepWindows binary under an@yane88/scope MUST audit.npmrcscope-registry mappings. Ensure any@yane88:registry=entry points to your internal registry,always-auth = true, and that no CI job falls through to public npm for that scope. Version-pin every internal@yane88/dependency. Review developer workstation~/.npm/_logsfor any recentinstall @yane88/*` line. Rotate any GitHub PAT / npm token / IDE license key that touched an affected workstation - the operator may already have IDE-configuration exfiltration - 3For Cluster B (
pyservercheckPolinRider EtherHiding): on any host thatpip install pyservercheck(or that pulled it transitively), consider it fully compromised. Do NOT rely onpip uninstall pyservercheckalone: the malicious.pthfile injected intosite-packageswill keep re-running on everypython/python3invocation. Manually grepsite-packagesfor the injected.pthand delete it; then rotate every credential accessible on the host - SSH keys, cloud metadata tokens (AWS/GCP/Azure), Vault, GitHub PATs, npm/pypi/rubygems tokens, browser session cookies, keychain entries. Watch outbound DNS/TCP for lookups against Ethereum RPC endpoints and JSON-RPC calls to the C2 contract at0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a. This is a DPRK/Lazarus North Korea IT-worker campaign - if this landed inside a corporate perimeter, expect follow-on account takeover, code-repo access, and (in the worst case) coordinated fraudulent-remote-worker enrolment - 4For Cluster C (
kendo-angular-window): confirm every Kendo UI dependency inpackage.jsonis a scoped@progress/kendo-angular-*package, NOT the unscopedkendo-angular-window. The legitimate Window component lives in@progress/kendo-angular-dialogs. If your build tooling has ever auto-installedkendo-angular-window, uninstall and audit downstream Angular apps for any injected postinstall/JS payload - 5For Cluster D (CWE-506 boilerplate takedowns): any lockfile hit means uninstall and rebuild; the advisory-level guidance is "consider the machine fully compromised, rotate secrets, do not assume removal is sufficient". Special attention for
@fdr-mar/promos-types: if your org uses an@fdr-*scope internally, treat it as a dependency-confusion probe and audit scope-registry routing per Cluster A guidance - 6*For Cluster E (`fuels-
Fuel Labs SDK typosquat)**: any dApp / Sway / Fuel Rust-VM team should confirm everyfuels-family install resolves to the legitimatefuelspackage or@fuel-ts/*scope. Never installfuels-core,fuels-forc,fuels-typegen, orfuels-versions` as unscoped packages - they are all malware. Rotate any wallet seed / RPC credential that touched a machine which pulled one - 7For Cluster F (EVM smart-contract-verifier typosquat cluster): any repo that submits contract verification to
sourcify.eth, Etherscan, Blockscout, or a chain-specific verifier from a CI job that installedverify-contract-viem,verify-contract-ethers,generate-schema-viem,generate-schema-ethers, orhyperliquid-composermust assume its most recent verification submissions may have been silently rewritten to hide backdoored bytecode. Re-verify affected contracts from a clean CI runner, and audit for any recently-deployed contract where the on-chain bytecode disagrees with your source-of-truth build - 8*For Cluster G (`@viertechjs/
dep-confusion probe)**: audit.npmrcfor any@viertech*scope resolver; ensure it routes to your internal registry withalways-auth = true. Baileys-based WhatsApp integrations should verify the dependency is@whiskeysockets/baileys, NOT@viertechjs/baileys` - 9For Cluster H (Mongo stack typosquats):
mongooseis a Node.js server-side ODM - a "React wrapper for Mongoose" does not exist. Anypackage.jsonline withreact-mongooseshould be deleted.express-mongo-limitshould be replaced with the legitimateexpress-rate-limit+rate-limit-mongopair - 10For Cluster I (
bamruclipboard/screen harvester): on any host that installedbamru, block outbound traffic tonew-pointer.vercel.appand grep proxy / firewall logs for prior connections to that domain. Rotate every credential that may have been in the clipboard during the exposure window: passwords, private keys, MFA seed backups, wallet mnemonics, cloud CLI tokens. Screen captures are also exfiltrated - if the affected host displayed sensitive documents on screen (contracts, PII, source code, dashboards), treat that content as leaked - 11For Cluster K (PyPI
gcphelpit/tallyboxlite): on any host that ranpip install gcphelpit(especially0.1.2or later), assume all local files accessible to the invoking user have been exfiltrated - rotate GCP service account keys,gcloudcached credentials, and any secret file in the user's home directory.tallyboxliteis lower-severity host reconnaissance but still ran arbitrary code at install: same uninstall-and-rebuild guidance - 12For all
npm installruns in CI, prefer--ignore-scripts- dep-confusion pkgs still typically ship postinstall/preinstall hooks - 13For all
pip installruns in CI, prefer--no-build-isolation+ explicit--only-binarywhere possible. Note:pyservercheck's.pthinjection primitive is triggered by ANY install path, not just source builds, so--only-binaryalone is not sufficient - addpyservercheck(and any variant) to your registry-mirror deny list - 14Verify none of the enumerated packages still resolves via your private mirror - internal caches (Nexus / Artifactory / Verdaccio / Sonatype / devpi) routinely keep serving yanked tarballs after the public takedown
References
- GitHubGHSA-p6mp-76cr-jhjq - pyservercheck (PyPI PolinRider EtherHiding stager v0.1.x)github.com
- GitHubGHSA-v22h-4j6c-58cm - @yane88/workbuddy (npm dep-confusion probe)github.com
- GitHubGHSA-2w3r-v82c-4rvg - @yane88/workbuddy-01 (npm dep-confusion probe)github.com
- GitHubGHSA-677c-x838-7qj5 - @yane88/workbuddy-02 (npm dep-confusion probe)github.com
- GitHubGHSA-qpjf-29xc-g688 - @yane88/workbuddy-03 (npm dep-confusion probe)github.com
- GitHubGHSA-6qjf-3c98-5gr7 - @yane88/listary (npm dep-confusion probe of Listary Windows launcher)github.com
- GitHubGHSA-46j3-wfp2-66m2 - @yane88/listary-01 (npm dep-confusion probe)github.com
- GitHubGHSA-rg2v-g672-8773 - @yane88/listary-02 (npm dep-confusion probe)github.com
- GitHubGHSA-xx48-j637-66x2 - @yane88/term-reqable (npm dep-confusion probe of Reqable API debugger)github.com
- GitHubGHSA-m76v-4h4c-w693 - @yane88/term-reqable-01 (npm dep-confusion probe)github.com
- GitHubGHSA-vq2v-vw6h-9g9f - @yane88/term-reqable-02 (npm dep-confusion probe)github.com
- GitHubGHSA-75h3-gh74-47p2 - @yane88/hexhub-client (npm dep-confusion probe)github.com
- GitHubGHSA-274r-44qv-6xwc - @yane88/ripgrep-win (npm dep-confusion probe)github.com
- GitHubGHSA-5qw7-3hqh-q33m - @yane88/idea-2026.2 (npm dep-confusion probe of IntelliJ IDEA 2026.2)github.com
- GitHubGHSA-2fmg-86jf-r56c - @yane88/idea-2026.2-01 (npm dep-confusion probe)github.com
- GitHubGHSA-fgwh-qm8c-9mv8 - @yane88/idea-2026.2-02 (npm dep-confusion probe)github.com
- GitHubGHSA-fw5q-2vvv-w862 - @yane88/idea-2026.2-03 (npm dep-confusion probe)github.com
- GitHubGHSA-xpjx-pwwq-qg46 - @yane88/idea-2026.2-04 (npm dep-confusion probe)github.com
- GitHubGHSA-mv54-8cx5-2fc9 - @yane88/idea-2026.2-05 (npm dep-confusion probe)github.com
- GitHubGHSA-j62v-qq84-cr9v - @yane88/idea-2026.2-06 (npm dep-confusion probe)github.com
- GitHubGHSA-jjx4-p3qc-rhrq - kendo-angular-window (npm Telerik/Progress Kendo UI typosquat)github.com
- GitHubGHSA-jhgv-vh9h-q3r9 - matrix-by-lmx (npm CWE-506 takedown)github.com
- GitHubGHSA-5x4x-f7h5-6p47 - randomunblockedwebsite (npm CWE-506 takedown)github.com
- GitHubGHSA-rxjr-qr5x-q4q7 - core_main (npm CWE-506 takedown)github.com
- GitHubGHSA-w63g-6crc-rq2w - quartz-core (npm typosquat of @quartz/core / @quartzds/core / jackyzha0/quartz)github.com
- GitHubGHSA-gj3w-q938-w6m6 - @fdr-mar/promos-types (npm dep-confusion candidate)github.com
- GitHubGHSA-82rr-x2r8-gjhm - fuels-core (npm Fuel Labs SDK typosquat)github.com
- GitHubGHSA-h4w6-844f-2fxw - fuels-forc (npm Fuel Labs SDK typosquat)github.com
- GitHubGHSA-c4wf-579x-f397 - fuels-typegen (npm Fuel Labs SDK typosquat)github.com
- GitHubGHSA-7478-v9hq-9835 - fuels-versions (npm Fuel Labs SDK typosquat, first disclosure)github.com
- GitHubGHSA-cxcx-864c-x6vp - fuels-versions (npm Fuel Labs SDK typosquat, duplicate disclosure)github.com
- GitHubGHSA-rhm2-cc4p-vfxq - verify-contract-viem (npm EVM verifier typosquat)github.com
- GitHubGHSA-cvw4-2h4c-hm3f - verify-contract-ethers (npm EVM verifier typosquat)github.com
- GitHubGHSA-72cf-ghpg-mj8h - generate-schema-viem (npm EVM verifier typosquat)github.com
- GitHubGHSA-3c7v-grhq-3m56 - generate-schema-ethers (npm EVM verifier typosquat)github.com
- GitHubGHSA-5v7v-27c5-fr8q - hyperliquid-composer (npm Hyperliquid DEX typosquat)github.com
- GitHubGHSA-3f73-cx58-g87j - @viertechjs/wb (npm dep-confusion probe)github.com
- GitHubGHSA-wcqj-8x6x-4pxr - @viertechjs/baileys (npm dep-confusion probe, WhatsApp/Baileys)github.com
- GitHubGHSA-62qr-2m9g-fm38 - @viertechjs/api (npm dep-confusion probe)github.com
- GitHubGHSA-wvgj-m2p9-jf3c - react-mongoose (npm MongoDB stack typosquat)github.com
- GitHubGHSA-rw8f-rf6x-jj3j - express-mongo-limit (npm MongoDB stack typosquat)github.com
- GitHubGHSA-jr4p-f775-3jjp - bamru (npm clipboard/screen harvester, C2 new-pointer.vercel.app)github.com
- GitHubGHSA-95gx-59fv-gfg6 - npx-oob-package (npm OOB DNS-callback probe)github.com
- GitHubGHSA-4894-fvv8-2p2j - cre-setup (npm CWE-506 takedown)github.com
- GitHubGHSA-9jm3-2h34-h9g3 - gcphelpit (PyPI GCP-help infostealer, campaign 2026-09-gcphelpit)github.com
- GitHubGHSA-x92w-4wvc-qx2w - tallyboxlite (PyPI pentest recon at install)github.com
- GitHubGitHub Advisory Database - recent npm malware advisoriesgithub.com
- GitHubGitHub Advisory Database - recent PyPI malware advisoriesgithub.com
- OpenSSFOpenSSF malicious-packages repositorygithub.com