# GitHub Advisory malware sweep - 2026-09-18 late + 2026-09-19 (npm `algamil7x.xyz` DNS-OOB scope expansion `@shared-web/utils`/`@shared-web/assets`/`@shared-runtime/modules`/`@insiderintelligence/googleadmanager` day 2; `test89-auth`/`test890-auth`/`test899-auth`/`test8999-auth` dep-confusion probe siblings of yesterday`s `test89078-auth`; on-chain Ethereum-C2 `tailwindcss-form@<=0.5.1` + `tailwindcss-forms-ui@<=0.5.2` day 2 of `0xa322E5f3...`; `@sanzoffc/baileys@<=3.0.4` newsletter-follower + unpinned `@whiskeysockets/eslint-config` github ref; `chai-as-indexed@<=7.2.8` `ipcheck-hashed.vercel.app` full-`process.env` exfil + `new Function()` RCE; `x509-escaping@0.0.0-0.0.2/1.0.1` Burp Collaborator `oastify.com` recon; `internallib_v949`, `sinful`, `openmct-heatmap`, `ac-polyfills` CWE-506; pip `py-venv-doctor@0.1.0/0.1.1` full-env-var telemetry exfil; pip `google-cloud-datacatalog-lineage-producer-client@9999`/`99999999`/`0.2.7` google-cloud-* dep-confusion sentinel; npm `keroeltop@99.99.99` malicious-domain probe)

> GHSA 2026-09-18 late + 2026-09-19: 4x npm `@shared-*` + `@insiderintelligence/*` scopes at sentinel `9.9.10` extend yesterday`s `algamil7x.xyz` DNS-OOB campaign into fresh internal-lookalike scopes (day 2, same operator); 4x `test89*-auth` dep-confusion probes continue the `test89078-auth` cluster; on-chain Ethereum-C2 `tailwindcss-form*` typosquats republish under `0xa322E5f3...` (day 2); `chai-as-indexed` POSTs the full `process.env` to `ipcheck-hashed.vercel.app` and evals the response; pip `py-venv-doctor` exfils environment variables via a fake healthcheck telemetry channel.

- Published: 2026-09-19
- Severity: high
- Kind: Advisory sweep - A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
- Ecosystems: npm, PyPI
- Scope: 20 packages, 26 compromised versions
- Tags: typosquat, dependency-confusion, infostealer, credential-theft, ci-cd-compromise, obfuscation, dns-exfiltration
- Also known as: 2026-09-19 GHSA npm+pip sweep, algamil7x.xyz DNS-OOB scope expansion (day 2, @shared-web/@shared-runtime/@insiderintelligence), test89*-auth dep-confusion probe siblings (day 2), tailwindcss-form/tailwindcss-forms-ui on-chain Ethereum C2 day 2 (0xa322E5f3...), @sanzoffc/baileys newsletter-follower + unpinned github ref (Baileys wave day 4), chai-as-indexed ipcheck-hashed.vercel.app full-env exfil + require-time RCE, x509-escaping Burp Collaborator OOB recon, py-venv-doctor full-env-var telemetry exfil, google-cloud-datacatalog-lineage-producer-client dep-confusion sentinel, keroeltop malicious-domain probe
- Detected by: GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, amazon-inspector, kam193/bad-packages, jaschadub/compromised-packages-check
- Incident ID: multi-2026-09-19-ghsa-malware-sweep

## Affected packages (20)

Only the exact versions listed were named by the source advisories. Other versions are not implicated.

| Package | Ecosystem | Compromised versions |
|---|---|---|
| [@insiderintelligence/googleadmanager](https://dependencywatch.io/package/npm/@insiderintelligence/googleadmanager) | npm | 9.9.10 |
| [@sanzoffc/baileys](https://dependencywatch.io/package/npm/@sanzoffc/baileys) | npm | <=3.0.4 |
| [@shared-runtime/modules](https://dependencywatch.io/package/npm/@shared-runtime/modules) | npm | 9.9.10 |
| [@shared-web/assets](https://dependencywatch.io/package/npm/@shared-web/assets) | npm | 9.9.10 |
| [@shared-web/utils](https://dependencywatch.io/package/npm/@shared-web/utils) | npm | 9.9.10 |
| [ac-polyfills](https://dependencywatch.io/package/npm/ac-polyfills) | npm | >=0 |
| [chai-as-indexed](https://dependencywatch.io/package/npm/chai-as-indexed) | npm | <=7.2.8 |
| [google-cloud-datacatalog-lineage-producer-client](https://dependencywatch.io/package/pypi/google-cloud-datacatalog-lineage-producer-client) | PyPI | 9999, 99999999, 0.2.7 |
| [internallib_v949](https://dependencywatch.io/package/npm/internallib_v949) | npm | >=0 |
| [keroeltop](https://dependencywatch.io/package/npm/keroeltop) | npm | 99.99.99 |
| [openmct-heatmap](https://dependencywatch.io/package/npm/openmct-heatmap) | npm | >=0 |
| [py-venv-doctor](https://dependencywatch.io/package/pypi/py-venv-doctor) | PyPI | 0.1.0, 0.1.1 |
| [sinful](https://dependencywatch.io/package/npm/sinful) | npm | >=0 |
| [tailwindcss-form](https://dependencywatch.io/package/npm/tailwindcss-form) | npm | <=0.5.1 |
| [tailwindcss-forms-ui](https://dependencywatch.io/package/npm/tailwindcss-forms-ui) | npm | <=0.5.2 |
| [test89-auth](https://dependencywatch.io/package/npm/test89-auth) | npm | >=0 |
| [test890-auth](https://dependencywatch.io/package/npm/test890-auth) | npm | >=0 |
| [test899-auth](https://dependencywatch.io/package/npm/test899-auth) | npm | >=0 |
| [test8999-auth](https://dependencywatch.io/package/npm/test8999-auth) | npm | >=0 |
| [x509-escaping](https://dependencywatch.io/package/npm/x509-escaping) | npm | 0.0.0, 0.0.1, 0.0.2, 1.0.1 |

## What happened

Between roughly 2026-09-18 12:00 UTC and 2026-09-19 12:00 UTC, GitHub Advisory Database published 20 new malware advisories — 18 npm and 2 pip. Today`s batch is dominated by continuations of the operator clusters catalogued yesterday: the `algamil7x.xyz` DNS-OOB operator is on day 2 with four fresh internal-lookalike scopes; the `tailwindcss-form*` on-chain-C2 operator is on day 2 with two more typosquats reusing the same Ethereum sender address; the `test89*-auth` dep-confusion pentest is on day 2 with four sibling packages; and the Baileys-wave ecosystem continues with a day 4 newsletter-follower (`@sanzoffc/baileys`). Two require-time RCE payloads (`chai-as-indexed`, one on-chain) and one full-env-var telemetry exfil (`py-venv-doctor`) elevate the batch severity to `high`.

## Cluster A - `algamil7x.xyz` DNS-OOB scope expansion (npm)

| Package | Version | GHSA | DNS prefix |
|---|---|---|---|
| `@shared-web/utils` | `9.9.10` | GHSA-29f7-pqf4-c94j | `swutils` |
| `@shared-web/assets` | `9.9.10` | GHSA-vmr9-5w3x-4v98 | `@shared-web/assets` (raw package name) |
| `@shared-runtime/modules` | `9.9.10` | GHSA-g85c-jph7-8q4r | `@shared-runtime/modules` |
| `@insiderintelligence/googleadmanager` | `9.9.10` | GHSA-76rx-jxhm-vhww | `googleadmanager` |

**The primitive.** Each package ships a `package.json` with `scripts.install: node index.js`. On `npm install`, the script loads a `lib/core.js` that resolves `os.userInfo().username`, `os.hostname()`, and `process.cwd()` basename via `module.constructor._load` (bypassing literal `require()` calls); domain names and API strings are stored as hex byte arrays in two per-package obfuscation files (`lib/a9b3de.js`+`lib/f8a2cd.js`, `lib/a74d1f.js`+`lib/f63c0e.js`, `lib/c5df9a.js`+`lib/b4ce8f.js`, `lib/g7h8i9.js`+`lib/h8i9j0.js`), reconstructed via `String.fromCharCode` at runtime. The reconstructed exfil chain is a DNS resolution query of the form `<prefix>-<user>-<host>-<cwd>.<ts>.oob.algamil7x.xyz`, and the operator sees the resolution in their authoritative DNS log.

**Same operator as yesterday`s `@tink/tink-link-core@9.9.10` (Cluster D of 2026-09-18 sweep)**: same DNS zone (`oob.algamil7x.xyz`), same sentinel version (`9.9.10`), same hex-array obfuscation pattern, same `module.constructor._load` evasion. Yesterday impersonated Tink open-banking SDK; today four fresh internal-lookalike scopes (`@shared-web/*`, `@shared-runtime/*`, `@insiderintelligence/*`). Treat any `9.9.10`-tagged internal-name lookalike as this operator until proven otherwise, and keep watching for day-3 expansion tomorrow.

## Cluster B - `test89*-auth` dep-confusion probe siblings (npm)

| Package | Sentinel version | GHSA |
|---|---|---|
| `test89-auth` | any | GHSA-7868-hxr7-g8r6 |
| `test890-auth` | any | GHSA-xvpv-wq7p-548c |
| `test899-auth` | any | GHSA-jf2q-w77c-99vv |
| `test8999-auth` | any | GHSA-25wf-vfrc-2r82 |

**Same operator as yesterday`s `test89078-auth@99.99.99`** (Cluster D of 2026-09-18 sweep) — same `preinstall: node index.js` primitive, same DNS-OOB primitive against `31ee29fe-db68-4fd3-86a2-2b707b9e95f0.dnshook.site`. GHSA published only the CWE-506 boilerplate on these four, but the naming lineage (four sequential numeric-suffix `test89*-auth` variants plus yesterday`s `test89078-auth`) is diagnostic: one dep-confusion pentest engagement iterating the numeric suffix in the same 48-hour window.

## Cluster C - On-chain Ethereum-C2 `tailwindcss-form*` typosquats (day 2) (npm)

| Package | Version | GHSA | Same Ethereum sender |
|---|---|---|---|
| `tailwindcss-form` | `<=0.5.1` | GHSA-xhr7-h7hc-7785 | `0xa322E5f3D311D3080e9aDC2490Ef6f0121063e1a` |
| `tailwindcss-forms-ui` | `<=0.5.2` | GHSA-fc5q-m33g-rp9c | `0xa322E5f3D311D3080e9aDC2490Ef6f0121063e1a` |

Same Ethereum sender address as yesterday`s `tailwindcss-form-utils`/`-form-ui` (Cluster C of 2026-09-18 sweep). Same primitive: impersonate `@tailwindlabs/tailwindcss-forms`, obfuscator.io control-flow-flattened string array, query multiple Ethereum JSON-RPC endpoints (`eth.publicnode.com`, `eth.drpc.org`, `1rpc.io/eth`, `eth-mainnet.public.blastapi.io`, `eth.blockscout.com`) for transactions authored by the hardcoded sender, decompress the transaction data (gzip/inflate/brotli), reconstruct a JavaScript payload, and execute via `child_process.spawn`. **The EtherHiding pattern is being iterated aggressively** — four packages across two days against the same on-chain sender. Every new transaction from that address is a fresh command pushed to every installed victim.

## Cluster D - `@sanzoffc/baileys` Baileys-wave day 4 (npm)

`@sanzoffc/baileys@<=3.0.4` (GHSA-grqc-r63w-6845). Continues the day 1 `plogme` (2026-09-16) → day 2 `jexkcode` (2026-09-17) → day 3 libsignal-hijack quad (Cluster A of 2026-09-18) Baileys wave.

Today`s variant is a nuisance-tier newsletter-follower — reconstructs an obfuscated URL to `https://raw.githubusercontent.com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json`, uses WhatsApp GraphQL mutations (`query_id: 7871414976211147`) with a base64+XOR-decoded `@newsletter` JID (XOR key `23`) to subscribe the infected account to attacker-specified newsletters 40 seconds after invocation.

**Additionally**, the manifest declares `@whiskeysockets/eslint-config` as an unpinned `github:` source with most other dependencies pinned to wildcards — same RCE-surface primitive as yesterday`s Cluster A packages. So the effective posture is: a nuisance payload today, an RCE surface waiting for the operator to flip.

## Cluster E - `chai-as-indexed` require-time full-`process.env` exfil + RCE (npm)

`chai-as-indexed@<=7.2.8` (GHSA-727r-6hg5-947x, MAL-2026-16293). Masquerades as a `chai` assertion-library plugin (impersonates `chai-as-promised`). On `require`:

1. Loads `./lib/initializeCaller`
2. POSTs the full `process.env` of the installer`s Node process to a base64-encoded endpoint: `https://ipcheck-hashed.vercel.app/api/auth/13b72bec1d4f2ee1c661`
3. The response body is passed to `new Function('require', responseBody)` and invoked with the real `require`

**Full remote code execution on every load**, and the exfil payload contains *every* environment variable — CI secrets, npm tokens, cloud provider credentials, database URLs. `--ignore-scripts` does not block this — it triggers on `require`, not on install. Egress-block `ipcheck-hashed.vercel.app` in CI.

## Cluster F - `x509-escaping` Burp Collaborator OOB recon (npm)

`x509-escaping@0.0.0-0.0.2/1.0.1` (GHSA-fq85-7xqm-cgj9, MAL-2025-889). `preinstall: node index.js` reads:

- Hostname, username, home directory
- DNS server config
- Working directory
- `/etc/passwd`, `/etc/hosts`

POSTs the collected data to `https://agumuj6lhw9yqopq6npl1nlgu70yorcg.oastify.com` (a Burp Collaborator payload URL the operator owns). Pentest-shaped — no persistent payload, install-time only — but the exfil is real and the harvested data is now on an attacker-controlled Burp endpoint.

## Cluster G - CWE-506 boilerplate takedowns (npm, likely dep-confusion probes)

| Package | GHSA | Notes |
|---|---|---|
| `internallib_v949` | GHSA-f863-m366-9cfm, GHSA-4qw5-jqr6-c4fj | `internallib_v<number>` dep-confusion sentinel |
| `sinful` | GHSA-2xjj-r8mc-xpf6 | No published analysis |
| `openmct-heatmap` | GHSA-qx52-2xq4-3x3v | NASA Open MCT extension impersonation |
| `ac-polyfills` | MAL-2026-782 (OSV-only) | `@ac`/`ac-*` internal-scope dep-confusion |

GitHub Advisory Database boilerplate only ("any computer that has this package installed should be considered fully compromised. All secrets and keys stored on that computer should be rotated"). Treat as `medium` — likely dep-confusion probes shaped like this week`s other probes, awaiting published payload analysis.

## Cluster H - pip `py-venv-doctor` full-env-var telemetry exfil

`py-venv-doctor@0.1.0/0.1.1` (GHSA-94w6-hr49-qjm7, MAL-2026-16296, campaign `2026-09-py-venv-doctor`). Overrides `setup.py`'s `install` command to execute during `pip install`, then sends a "fake healthcheck report" telemetry channel that transmits the *full* environment variable set — including every sensitive variable in scope of `pip install` (CI secrets, cloud provider credentials, database URLs). Confirmed infostealer, not a probe.

## Cluster I - pip `google-cloud-datacatalog-lineage-producer-client` google-cloud-* dep-confusion

`google-cloud-datacatalog-lineage-producer-client@9999/99999999/0.2.7` (MAL-2024-12279). OSV-tracked from 2024 but freshly relisted in today`s GitHub Advisory sweep. Three sentinel-tier version numbers on a plausibly-internal google-cloud-* name — classic dep-confusion resolution-attack lure against internal Google/GCP developer registries that mirror the `google-cloud-*` namespace.

## Cluster J - `keroeltop@99.99.99` malicious-domain probe (npm)

`keroeltop@99.99.99` (GHSA-gg5m-rqpp-c9xf, MAL-2026-16297). OpenSSF Package Analysis flag only: "The package communicates with a domain associated with malicious activity." Single sentinel version, no detailed payload disclosure yet — treat as `medium` pending IOC publication.

## Cross-operator patterns worth flagging

1. **The `algamil7x.xyz` operator is on day 2.** Yesterday one package, today four — the operator is scaling. Block the DNS zone at your resolver; expect day 3 tomorrow.
2. **The `tailwindcss-form*` on-chain operator is on day 2** and still using the same `0xa322E5f3...` Ethereum sender. Detection cost stays asymmetric: no domain to block, only outbound Ethereum-RPC traffic from build environments to alert on.
3. **The `test89*-auth` engagement is on day 2** with four numeric-suffix siblings of yesterday`s `test89078-auth`. Same DNS hook, same primitive.
4. **The Baileys wave is on day 4** and now includes both nuisance newsletter-followers and full install-time RCE via unpinned `github:` dependencies. Treat any Baileys wrapper as suspect.
5. **`chai-as-indexed` is a require-time full-`process.env` exfil + RCE** — the highest-severity single package in today`s batch. Every environment variable the parent Node process could see is on the operator`s server.

## Registry state

All packages above are flagged as malware on npm and PyPI and quarantined at the time of writing. Private mirrors that cached tarballs before quarantine keep serving the malicious versions; network-edge egress blocks on `oob.algamil7x.xyz`, `dnshook.site`, `ipcheck-hashed.vercel.app`, `oastify.com`, and outbound Ethereum-JSON-RPC calls from CI are the durable mitigations.

## Discovery credits

`GitHub Advisory Database`, `OpenSSF malicious-packages`, `OpenSSF Package Analysis`, `amazon-inspector`, `kam193/bad-packages`, `jaschadub/compromised-packages-check`. Per-package IOC details drawn verbatim from GHSA advisory bodies published between 2026-09-18 12:00 UTC and 2026-09-19 12:00 UTC.

## Impact

- **Cluster A — 4x npm `algamil7x.xyz` DNS-OOB scope expansion (day 2 of yesterday`s Cluster D operator)**: `@shared-web/utils@9.9.10` (GHSA-29f7-pqf4-c94j, MAL-2026-16292), `@shared-web/assets@9.9.10` (GHSA-vmr9-5w3x-4v98, MAL-2026-16283), `@shared-runtime/modules@9.9.10` (GHSA-g85c-jph7-8q4r, MAL-2026-16291), `@insiderintelligence/googleadmanager@9.9.10` (GHSA-76rx-jxhm-vhww, MAL-2026-16290). All four declare `scripts.install: node index.js`; the install script loads `lib/core.js` which resolves `os.userInfo().username`, `os.hostname()`, and `process.cwd()` basename, then DNS-resolves subdomains of `oob.algamil7x.xyz` (the *same* zone yesterday`s `@tink/tink-link-core@9.9.10` exfiltrated to). Uniform code style: `String.fromCharCode` hex-array obfuscation in two per-package `lib/<random>.js` files, `module.constructor._load` used in place of literal `require()`, prefix each package chooses (`swutils`, `@shared-runtime/modules`, `@shared-web/assets`, `googleadmanager`) is the campaign identifier the operator sees in their authoritative DNS log. **Day 2 of the same operator: yesterday `@tink/tink-link-core` (Tink open-banking SDK impersonation), today four fresh internal-lookalike scopes** — treat any `9.9.10`-tagged internal-name lookalike as this operator until proven otherwise
- **Cluster B — 4x npm `test89*-auth` dep-confusion probe siblings**: `test89-auth` (GHSA-7868-hxr7-g8r6, MAL-2026-16288), `test890-auth` (GHSA-xvpv-wq7p-548c, MAL-2026-16289), `test899-auth` (GHSA-jf2q-w77c-99vv, MAL-2026-16285), `test8999-auth` (GHSA-25wf-vfrc-2r82, MAL-2026-16286). Same operator as yesterday`s `test89078-auth@99.99.99` (Cluster D of 2026-09-18 sweep), same preinstall pattern, same DNS-OOB primitive against `31ee29fe-db68-4fd3-86a2-2b707b9e95f0.dnshook.site`. GHSA carries only the CWE-506 boilerplate for these four, but the naming lineage (four sequential `test89-`, `test890-`, `test899-`, `test8999-`, and yesterday`s `test89078-`) is diagnostic: this is one dep-confusion pentest engagement iterating the numeric suffix. Pentest-shaped, but the payload nevertheless exfils hostname/username to a public DNS-OOB service — treat installs as intelligence-gathering hits
- **Cluster C — 2x npm on-chain Ethereum-C2 `tailwindcss-form*` typosquats (day 2 of yesterday`s Cluster C operator)**: `tailwindcss-form@<=0.5.1` (GHSA-xhr7-h7hc-7785) and `tailwindcss-forms-ui@<=0.5.2` (GHSA-fc5q-m33g-rp9c, MAL-2026-16295). Same primitive as yesterday`s `tailwindcss-form-utils`/`-form-ui` (Cluster C of 2026-09-18): impersonate `@tailwindlabs/tailwindcss-forms`, obfuscator.io string-array with control-flow flattening, query multiple Ethereum JSON-RPC endpoints (`eth.publicnode.com`, `eth.drpc.org`, `1rpc.io/eth`, `eth-mainnet.public.blastapi.io`, `eth.blockscout.com`), pull txlist for transactions authored by the hardcoded sender `0xa322E5f3D311D3080e9aDC2490Ef6f0121063e1a`, decompress the transaction data (gzip/inflate/brotli), reconstruct a JavaScript payload, and execute via `child_process.spawn`. **This is the same Ethereum address as yesterday`s pair** — the same on-chain command channel is now four packages deep across two days, and the EtherHiding pattern is being iterated aggressively
- **Cluster D — 1x npm `@sanzoffc/baileys@<=3.0.4` newsletter-follower + unpinned github: RCE surface (day 4 of Baileys wave)**: GHSA-grqc-r63w-6845. Continues the `plogme` (2026-09-16) → `jexkcode` (2026-09-17) → yesterday`s libsignal-hijack quad (Cluster A of 2026-09-18) Baileys wave. This one is a nuisance-tier newsletter-follower: reconstructs an obfuscated URL to `https://raw.githubusercontent.com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json`, uses WhatsApp GraphQL mutations (`query_id: 7871414976211147`) with a base64+XOR-decoded `@newsletter` JID (XOR key `23`) to subscribe the infected account to attacker-specified newsletters 40 seconds after invocation. Additionally, the manifest declares `@whiskeysockets/eslint-config` as an unpinned github: source — same RCE-surface primitive as yesterday`s Cluster A packages. Ship it as day 4 of the Baileys wave
- **Cluster E — 1x npm `chai-as-indexed@<=7.2.8` require-time RCE via `ipcheck-hashed.vercel.app`**: GHSA-727r-6hg5-947x, MAL-2026-16293. Masquerades as a `chai` assertion-library plugin (impersonates `chai-as-promised` naming). On require, POSTs the *entire* `process.env` of the installer`s Node process (every environment variable — CI secrets, npm tokens, cloud provider credentials) to a base64-encoded endpoint `https://ipcheck-hashed.vercel.app/api/auth/13b72bec1d4f2ee1c661` (base64: `aHR0cHM6Ly9pcGNoZWNrLWhhc2hlZC52ZXJjZWwuYXBwL2FwaS9hdXRoLzEzYjcyYmVjMWQ0ZjJlZTFjNjYx`). The response body is passed to `new Function('require', responseBody)` and invoked with the real `require`, enabling arbitrary remote code execution on every load — not just install-time
- **Cluster F — 1x npm `x509-escaping` Burp Collaborator OOB recon**: GHSA-fq85-7xqm-cgj9, MAL-2025-889. `x509-escaping@0.0.0-0.0.2` + `1.0.1`. Preinstall: `node index.js`; the script harvests hostname, username, home directory, DNS server, working directory, plus reads `/etc/passwd` and `/etc/hosts`, then POSTs the data to `https://agumuj6lhw9yqopq6npl1nlgu70yorcg.oastify.com` (Burp Collaborator payload URL). Same posture as `x509-escaping` and other `-escaping`-family reconnaissance packages: dep-confusion tactic, install-time only, pentest-shaped but the harvested data is on a Burp Collaborator endpoint the operator owns
- **Cluster G — 4x npm CWE-506 boilerplate takedowns (no published analysis; likely dep-confusion probes)**: `internallib_v949` (GHSA-f863-m366-9cfm, GHSA-4qw5-jqr6-c4fj, MAL-2026-16294) — the name pattern (`internallib_v<number>`) is a canonical dep-confusion sentinel; `sinful` (GHSA-2xjj-r8mc-xpf6, MAL-2026-16284); `openmct-heatmap` (GHSA-qx52-2xq4-3x3v, MAL-2026-16287) — impersonation of NASA`s Open MCT visualisation extensions; `ac-polyfills` (MAL-2026-782 — OSV-only, no GHSA at the time of writing) — dep-confusion of the `@ac`/`ac-*` internal scope pattern. All four flagged by GitHub Advisory Database with only the CWE-506 boilerplate warning ("any computer that has this package installed should be considered fully compromised. All secrets and keys stored on that computer should be rotated"). Treat as `medium` pending published payload analysis
- **Cluster H — pip `py-venv-doctor@0.1.0/0.1.1` full-env-var telemetry exfil**: GHSA-94w6-hr49-qjm7, MAL-2026-16296 (campaign `2026-09-py-venv-doctor`). Overrides `setup.py`'s `install` command to execute during `pip install`, then posts a "fake healthcheck report" telemetry channel that transmits "the full environment variable set, including any sensitive variables". Confirmed infostealer, not a probe. Same operator-shaped pattern as this week`s `requests-*@2.34.2` setup.py-override cluster
- **Cluster I — pip `google-cloud-datacatalog-lineage-producer-client@9999`/`99999999`/`0.2.7` google-cloud-* dep-confusion**: MAL-2024-12279 (OSV-only, backfilled to 2026-09-18 sweep). Three sentinel-tier version numbers on a plausibly-internal google-cloud-* name — classic dep-confusion resolution-attack lure targeting any internal Google/GCP developer registry that mirrors `google-cloud-*` names. The `9999`/`99999999` combo is a hallmark of the same operator that has been publishing `google-cloud-*` dep-confusion probes since at least 2024
- **Cluster J — 1x npm `keroeltop@99.99.99` malicious-domain probe**: GHSA-gg5m-rqpp-c9xf, MAL-2026-16297. OpenSSF Package Analysis flag: "The package communicates with a domain associated with malicious activity." Single sentinel version `99.99.99`, no detailed payload disclosure at time of writing. Treat as `medium` pending IOC publication

## What to do

1. Grep every `package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`, `package.json`, `requirements.txt`, `Pipfile.lock`, and `poetry.lock` in your org for every package name in Clusters A through J. Uninstall on hit, wipe `node_modules`/`.venv`, delete the lockfile, rebuild against a clean cache. Clusters A, B, C, D, E, F, H include real payloads (DNS exfil, on-chain RCE, require-time env var exfil, Burp Collab OOB recon, install-time env var telemetry) — a hit is a compromise, not a warning
2. **For Cluster A (`algamil7x.xyz` scope expansion) + Cluster B (`test89*-auth` dep-confusion)**: any host that `npm install`ed `@shared-web/utils`, `@shared-web/assets`, `@shared-runtime/modules`, `@insiderintelligence/googleadmanager`, `test89-auth`, `test890-auth`, `test899-auth`, or `test8999-auth` DNS-resolved a label carrying hostname/username. Rotate credentials accessible from that host, block `oob.algamil7x.xyz` and `31ee29fe-db68-4fd3-86a2-2b707b9e95f0.dnshook.site` at your resolver, and if you maintain internal `@shared-web`, `@shared-runtime`, `@insiderintelligence`, or `test89*` scopes, pin them to your internal registry with `.npmrc` and configure the internal registry to refuse public-npm publishes under the same names. Sentinel versions `9.9.10` and `99.99.99` are classic dep-confusion resolution-attack markers
3. **For Cluster C on-chain-C2 `tailwindcss-form*` (day 2)**: no domain to block — the command channel is Ethereum mainnet transactions from `0xa322E5f3D311D3080e9aDC2490Ef6f0121063e1a`. Detection: alert on any `child_process.spawn` in a build environment, alert on outbound TCP to `*.publicnode.com`, `eth.drpc.org`, `1rpc.io`, `eth-mainnet.public.blastapi.io`, and blockscout instances from build environments (these should never appear in a legitimate frontend build), and pin `@tailwindcss/forms` (correct name) explicitly in every project — the four typosquats span two days and are ranking in npm search results
4. **For Cluster D `@sanzoffc/baileys`**: uninstall on hit, note that any connected WhatsApp account with the package running silently subscribes to `skyzopedia/NewsletterID/VIP_Push.json` newsletter list 40 seconds after invocation. Additionally, the unpinned `github:` dependency on `@whiskeysockets/eslint-config` grants install-time RCE surface — audit that host as if it had run arbitrary code. Extend your registry denylist to any Baileys wrapper you have not personally vetted
5. **For Cluster E `chai-as-indexed`**: `--ignore-scripts` does NOT block this — it triggers on `require`. Any Node process that loaded this package POSTed its complete `process.env` (every environment variable) to `ipcheck-hashed.vercel.app/api/auth/13b72bec1d4f2ee1c661`. Assume every environment variable the process could see (CI secrets, npm tokens, AWS/GCP/Azure creds, database URLs) is compromised, and rotate all of them. Block `ipcheck-hashed.vercel.app` at CI egress
6. **For Cluster F `x509-escaping`**: uninstall, rotate credentials, block `oastify.com` (Burp Collaborator) at CI egress. Any host that installed the package exfiltrated `/etc/passwd`, `/etc/hosts`, DNS server config, hostname, and username to a Burp Collaborator subdomain the operator owns. Even if legitimate red-team, treat the exfil as harvested until you know otherwise
7. **For Cluster G CWE-506 boilerplate takedowns**: uninstall on hit, rotate env values as a precaution. These are pending published analysis — treat any of them as install-and-forget malware until a vendor publishes IOCs. Consider extending your registry denylist to `internallib_*`, `openmct-*`, `ac-polyfills`
8. **For Cluster H `py-venv-doctor`**: `pip uninstall py-venv-doctor`. The install-time payload exfiltrated the *entire* environment-variable set to the operator; rotate every credential visible to `pip install` in that environment. Add `pip install --no-binary :all: --isolated` to CI where possible to block setup.py-side attack paths
9. **For Cluster I `google-cloud-datacatalog-lineage-producer-client`**: if you maintain an internal `google-cloud-*` package under this exact name, pin it to your internal registry and refuse public-PyPI publishes under the same name. The `9999`/`99999999` sentinel-version pair is the classic dep-confusion resolution attack against internal mirrors
10. **For Cluster J `keroeltop`**: uninstall on hit, rotate credentials. IOC disclosure is pending — assume the sentinel version `99.99.99` behaves like other dep-confusion probes until analysis publishes
11. For every `npm install` in CI, prefer `--ignore-scripts` or an equivalent lockfile-consumer mode that blocks pre/post-install hooks. This blocks Clusters A, B, F, and H at install; but does NOT block Cluster C (`require`-time on-chain), Cluster D (`require`-time GraphQL), or Cluster E (`require`-time RCE). Layer with egress denylists on `oob.algamil7x.xyz`, `dnshook.site`, `ipcheck-hashed.vercel.app`, `oastify.com`, `webhook.site`, and `*.publicnode.com`/`drpc.org`/`1rpc.io`/`eth.blockscout.com`/`eth-mainnet.public.blastapi.io` (or, for legitimate Web3 workloads, alert-only on Ethereum RPCs from build environments)
12. Add every specific package name below to your internal private-registry deny-list for at least 30 days. Extend your existing pin-lists with `@shared-web/*`, `@shared-runtime/*`, `@insiderintelligence/*`, `@sanzoffc/baileys`, `test89*-auth`, `chai-as-*`, `openmct-*`, `internallib_*`, `ac-polyfills`, `keroeltop`, `x509-escaping`, `google-cloud-datacatalog-lineage-producer-client`, `py-venv-doctor`, and any Baileys wrapper you have not personally vetted

## Check your own dependencies

- Check a package-lock.json against this incident: https://dependencywatch.io/check/package-lock-json
- Check a requirements.txt against this incident: https://dependencywatch.io/check/requirements-txt

The scan runs entirely in the browser; lockfile contents are never uploaded.

## References

- [GitHub Advisory Database - recent malware advisories](https://github.com/advisories?query=type%3Amalware&sort=published-desc) - GitHub
- [GHSA-gg5m-rqpp-c9xf - keroeltop (Cluster J - malicious-domain probe)](https://github.com/advisories/GHSA-gg5m-rqpp-c9xf) - GitHub
- [GHSA-94w6-hr49-qjm7 - py-venv-doctor (Cluster H - pip full-env-var telemetry exfil)](https://github.com/advisories/GHSA-94w6-hr49-qjm7) - GitHub
- [GHSA-29f7-pqf4-c94j - @shared-web/utils (Cluster A - algamil7x.xyz DNS-OOB day 2)](https://github.com/advisories/GHSA-29f7-pqf4-c94j) - GitHub
- [GHSA-vmr9-5w3x-4v98 - @shared-web/assets (Cluster A)](https://github.com/advisories/GHSA-vmr9-5w3x-4v98) - GitHub
- [GHSA-g85c-jph7-8q4r - @shared-runtime/modules (Cluster A)](https://github.com/advisories/GHSA-g85c-jph7-8q4r) - GitHub
- [GHSA-76rx-jxhm-vhww - @insiderintelligence/googleadmanager (Cluster A)](https://github.com/advisories/GHSA-76rx-jxhm-vhww) - GitHub
- [GHSA-7868-hxr7-g8r6 - test89-auth (Cluster B - dep-confusion probe siblings)](https://github.com/advisories/GHSA-7868-hxr7-g8r6) - GitHub
- [GHSA-xvpv-wq7p-548c - test890-auth (Cluster B)](https://github.com/advisories/GHSA-xvpv-wq7p-548c) - GitHub
- [GHSA-jf2q-w77c-99vv - test899-auth (Cluster B)](https://github.com/advisories/GHSA-jf2q-w77c-99vv) - GitHub
- [GHSA-25wf-vfrc-2r82 - test8999-auth (Cluster B)](https://github.com/advisories/GHSA-25wf-vfrc-2r82) - GitHub
- [GHSA-xhr7-h7hc-7785 - tailwindcss-form (Cluster C - on-chain ETH C2 day 2)](https://github.com/advisories/GHSA-xhr7-h7hc-7785) - GitHub
- [GHSA-fc5q-m33g-rp9c - tailwindcss-forms-ui (Cluster C)](https://github.com/advisories/GHSA-fc5q-m33g-rp9c) - GitHub
- [GHSA-grqc-r63w-6845 - @sanzoffc/baileys (Cluster D - Baileys wave day 4)](https://github.com/advisories/GHSA-grqc-r63w-6845) - GitHub
- [GHSA-727r-6hg5-947x - chai-as-indexed (Cluster E - ipcheck-hashed.vercel.app env exfil + RCE)](https://github.com/advisories/GHSA-727r-6hg5-947x) - GitHub
- [GHSA-fq85-7xqm-cgj9 - x509-escaping (Cluster F - Burp Collab OOB recon)](https://github.com/advisories/GHSA-fq85-7xqm-cgj9) - GitHub
- [GHSA-f863-m366-9cfm - internallib_v949 (Cluster G - CWE-506 boilerplate)](https://github.com/advisories/GHSA-f863-m366-9cfm) - GitHub
- [GHSA-2xjj-r8mc-xpf6 - sinful (Cluster G)](https://github.com/advisories/GHSA-2xjj-r8mc-xpf6) - GitHub
- [GHSA-qx52-2xq4-3x3v - openmct-heatmap (Cluster G)](https://github.com/advisories/GHSA-qx52-2xq4-3x3v) - GitHub
- [jaschadub/compromised-packages-check - Sep 18-19 2026 sweep](https://github.com/jaschadub/compromised-packages-check/pull/133) - jaschadub
- [OpenSSF malicious-packages repository](https://github.com/ossf/malicious-packages) - OpenSSF

---

Canonical page: https://dependencywatch.io/incident/multi-2026-09-19-ghsa-malware-sweep
Markdown version: https://dependencywatch.io/incident/multi-2026-09-19-ghsa-malware-sweep.md
Site index for agents: https://dependencywatch.io/llms.txt
DependencyWatch.io is operated by Precursor Security (https://precursorsecurity.com).
