Feed
HighAdvisory sweepPublished 23 Sept 202676 packages · 122 versions

GitHub Advisory malware sweep - 2026-09-22 (late) + 2026-09-23 (npm `@tvg-mar/*` + `@user-services/web-components` `oob.algamil7x.xyz` DNS-OOB day 6 at `9.9.10`; `hardhat-hold` axios-loader RCE typosquat wave extension; `chai-as-viem` + `chai-logger` chai/pino/jsonspack axios-loader family extension; `envforge/envparse` 6-package coordinated typosquat batch; `@wizloft/harness-*` 15-package Aug-Sep buildup batch quarantine; `oracle-redis` + `turbo-ws` transitive-dependency trojans; `@vitemirrorte/element-plus-vite-cli` `npmjs.it.com` mall4cloud-react-targeted RAT; `@gsutevil/hta-stage` Windows HTA/WSH MSI loader; org-internal dep-confusion cluster (`@tesla-insurance`, `devplatform-sdk`, `uolcs-host-uol-anuncios-fe`, `bnpl-blocks-*`, `bigops-*`, `agora402-payment-utils`, `ubiquiti-agents-link-mcp`, `internallib_v497/550` at RFC1918 `10.0.5.109`, `cisco-github-simple` oastify.com); pip `auclean` cloud-credential infostealer + `snap-queue`/`crypto-trader-py`/`poly-check-b` silent-install campaign + `kerokwis` pypi+rubygems telemetry; pentest `cloushaar-poc-exfil-91827` pip; ~60 random-name bulk quarantines)

Summary

GHSA 2026-09-22 (late) + 2026-09-23: ~120 new npm advisories + 5 pip + 2 rubygems. Day 6 of the oob.algamil7x.xyz DNS-OOB operator adds @tvg-mar/* and @user-services/web-components at 9.9.10. @vitemirrorte/element-plus-vite-cli@2.9.1 is a full Node RAT with npmjs.it.com C2 targeting mall4cloud-react. pip auclean steals cloud credentials.

dependency-confusiontyposquatdns-exfiltrationcredential-theftobfuscationci-cd-compromiseinfostealeraccount-takeover
Incident type
Advisory sweep. A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · Amazon Inspector · ESTsecurity · kam193/bad-packages · jaschadub/compromised-packages-check
Also known as
2026-09-23 GHSA npm sweep · @tvg-mar + @user-services algamil7x.xyz day 6 · hardhat-hold axios-loader RCE typosquat extension · chai-as-viem + chai-logger jsonspack.com family · envforge/envparse 6-package coordinated batch · @wizloft/harness 15-package batch quarantine · oracle-redis + turbo-ws transitive-dep trojans · @vitemirrorte/element-plus-vite-cli mall4cloud-react RAT · @gsutevil/hta-stage Windows HTA/WSH loader · auclean pip cloud-credential infostealer · 2026-09-snap-queue campaign
Ecosystems
npmPyPIRubyGems
Packages tracked
76

What happened

Between roughly 2026-09-22 12:00 UTC and 2026-09-23 12:00 UTC, GitHub Advisory Database (plus the OpenSSF malicious-packages bulk export and Amazon Inspector's IN-MAL feed) published approximately 120 new npm malware advisories, 5 pip advisories, and 2 rubygems advisories. The window is dominated by three major continuations (algamil7x.xyz DNS-OOB day 6, hardhat-* axios-loader RCE wave, chai-* jsonspack family) plus one fully-featured targeted RAT (@vitemirrorte/element-plus-vite-cli), one Windows HTA/WSH staging payload (@gsutevil/hta-stage), one confirmed cloud-credential infostealer (pip auclean), plus large late-catch batch quarantines.

Cluster A - @tvg-mar/* + @user-services/web-components oob.algamil7x.xyz DNS-OOB (day 6)

PackageVersionGHSAMAL
@tvg-mar/tvg-promos-atomic-ui9.9.10GHSA-fvh3-76xv-7978MAL-2026-16415
@tvg-mar/promos-context9.9.10GHSA-gmpx-wq8f-4q86-
@tvg-mar/promos-gtm9.9.10GHSA-4mmr-x347-r6gv-
@tvg-mar/storyblok-bridge9.9.10GHSA-r788-p8wq-7672-
@tvg-mar/utils9.9.10GHSA-g5mj-6q8x-7cj6-
@user-services/web-components9.9.10GHSA-6q28-qx7w-pv4x-

All six packages match the algamil7x install-chain verbatim: scripts.install: node index.js loads a runtime/support/telemetry/probe/impl.js module which reads os.userInfo().username, os.hostname(), and process.cwd() basename via module.constructor._load (indirect Node builtin resolution to defeat static analysis), concatenates with a timestamp and a per-package prefix, and issues a dns.resolve4 on <prefix>-<user>-<host>-<cwd>.<ts>.oob.algamil7x.xyz. Sibling probe/*.js files carry String.fromCharCode hex-array obfuscation of method names and destination domain plus telemetry/connectivity probe cover-story comments.

Day tally so far: day 1 (2026-09-18, @tink/tink-link-core@9.9.10, tinkcore), day 2 (2026-09-19, four @shared-web/@shared-runtime/@insiderintelligence packages), day 3 (2026-09-20 quiet), day 4 (2026-09-21, @baanx/solana-lib@9.9.9/9.9.10), day 5 (2026-09-22, @baanx/abis + @baanx/blockchain-config at 9.9.11), day 6 (today, 6 more packages under @tvg-mar and @user-services, all at 9.9.10). The operator is now iterating scope names roughly daily but keeping the primitive identical.

Cluster B - hardhat-hold axios-loader RCE typosquat wave extension

hardhat-hold@2.0.1 (2026-07-24) and @2.21.0 (2026-07-31), quarantined by npm 2026-09-23 00:09 UTC. Fourth hardhat-* in the Ethereum-toolchain typosquat wave that broke yesterday with hardhat-base, hardhat-core, hardhat-devkit. Late-catch of a Jul publish that npm review picked up two months after the fact. Payload class matches the family: detached child process + base64-decoded remote URL + axios POST + Function.constructor eval. Same operator, same infrastructure (ipcheck-hashed.vercel.app for the sibling hardhat-core).

Cluster C - chai-* axios-loader RCE family extension

PackageVersionGHSANotes
chai-as-viem(holder only)GHSA-88fm-v2m3-mx8xQuarantined 2026-09-22 18:20 UTC. Viem Ethereum-client lookalike. Register-continuation drop
chai-logger3.0.2GHSA-fv5h-7hj3-xq5r~4 MB obfuscated payload at import-time; pino cover files; axios inside obfuscated code; author = jsonspack.com

Extends the family first catalogued as chai-testing in the 2026-09-21 sweep. Signature: chai/pino cover story + axios-loader RCE + jsonspack.com author.

Dedup note: chai-tracker versions 1.1.0-1.1.3 and 1.2.1 are ALREADY catalogued in the 2026-08-10 sweep. Today's 2026-09-23 npm-side quarantine (GHSA-xvr2-rmx5-mrv3) is the formal namespace takedown of a package OpenSSF flagged 6 weeks ago. This sweep does not re-add chai-tracker.

Cluster D - envforge/envparse 6-package coordinated typosquat batch

PackageGHSAQuarantined
envparse2GHSA-q747-c2cv-gfhj2026-09-22 18:21 UTC
envparse3GHSA-vq77-3r62-c2cx2026-09-22 18:21 UTC
envforge2GHSA-h8xg-3hfp-rx6q2026-09-22 18:21 UTC
envforge3GHSA-7chm-5cxc-2wx22026-09-22 18:21 UTC
better-envforgeGHSA-3h54-43fv-m8222026-09-22 18:21 UTC
node-env-bufferGHSA-2g29-f3qp-c7gf2026-09-22 18:21 UTC

All six quarantined by npm in a ~90-second window. Coordinated multi-name typosquat drop against the .env/dotenv ecosystem. GHSA bodies are generic CWE-506 boilerplate; the per-package payload is not disclosed but the batch pattern implies a real one.

Cluster E - @wizloft/harness-* 15-package batch quarantine

All 15 quarantined by npm in a 4-minute window on 2026-09-23 00:20 UTC. Alpha/beta publishes ran from 2026-08-17 through 2026-09-06 - a ~5-week buildup. The 15 packages divide across three implied roles - CLI adapters, plugin harness, and memory/kernel core - which matches a "testing/CI harness" theme (see the earlier stillm4ddpocs-rtest-* sweep from 2026-08-23 for a comparable pattern). CWE-506 boilerplate advisories; specific payload not disclosed.

Cluster F - Transitive-dependency trojan (oracle-redis + turbo-ws)

PackageVersionGHSADelivery
oracle-redis5.11.3GHSA-8m7m-r8mw-mvq2Declared deps redis-type-intel@^1.10.5 + pino-ulid@^2.12.2 (never imported by oracle-redis code) - lifecycle scripts fire during transitive install
turbo-ws1.0.0GHSA-49rw-43cc-8cmhDeclared dep node-net-pool as HTTPS tarball on an unrelated GitHub account; postinstall loads the fetched tarball with no integrity check

Both impersonate legitimate names (ioredis, WebSocket "turbo" utilities). The oracle-redis case copies the ioredis README verbatim and points the repo URL at luin/ioredis for camouflage. Same architectural class as the 2026-09-22 bytepack-probe-a7x3 - malicious code injected via the dependency graph rather than the target package itself. --ignore-scripts blocks these.

Cluster G - @vitemirrorte/element-plus-vite-cli@2.9.1 mall4cloud-react-targeted RAT

Highest-severity single package of the sweep (MAL-2026-16401, GHSA-j7hr-ff2j-rgv6).

Persistence: agent deployed to ~/.gradle/caches/ at install-time - a directory that survives npm install/npm uninstall, is on the developer PATH via Gradle wrapper scripts, and is rarely audited during incident response.

C2: https://npmjs.it.com - a typosquat of npmjs.com built to inherit implicit trust when a security engineer scrolls the process list. Registers each install with hostname, os.userInfo().username, os.type(), os.release(), and a persistent agent_id.

Remote-control protocol:

  • exec opcode - arbitrary shell command execution
  • read opcode - fs.readFileSync on any path, exfiltrated back
  • upload/delete/move opcodes - filesystem write operations
  • ps/ls opcodes - process and directory enumeration

Activation gate: the RAT stays dormant unless the current workspace fingerprints as mall4cloud-react (an open-source Chinese e-commerce reference project popular in mid-2026 tutorials). This is a targeted supply-chain attack: the operator publishes broadly but the payload only fires against developers who cloned the specific target repo. Any dormant install can be re-activated by a future republish that widens the workspace-name whitelist.

Cluster H - @gsutevil/hta-stage Windows HTA/WSH MSI loader

@gsutevil/hta-stage@>=1.62.0 (GHSA-95xp-29r3-v466). Windows-only staging payload:

  1. Disables Windows Script Host anti-malware scanning via registry-modification of HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings and equivalent HKCU keys
  2. Collects computer name and username; beacons to attacker infrastructure
  3. Cleanup phase: terminates any running python.exe processes and removes any prior implant files
  4. Downloads and silently installs MSI packages from attacker-controlled servers
  5. All sensitive identifiers (WScript.Shell, ScriptControl, .exe, MSI URLs) reconstructed at runtime from String.fromCharCode byte arrays

Same TTP class as the Roblox-TS Windows RAT family tracked earlier in the corpus but with the MSI-download escalation making it a full multi-stage delivery mechanism rather than a single-shot dropper.

Cluster I - pip infostealer / campaigns

PackageVersionGHSACampaignNotes
auclean0.4.2/0.4.3/0.4.4GHSA-v257-9gjr-rv2j2026-09-aucleanCloud-credential infostealer: fingerprints env + network, targets cloud credentials, exfiltrates
snap-queue1.0.0GHSA-3v8f-m5rm-8mv32026-09-snap-queuesetup.py install-command override; payload file missing from sample
crypto-trader-py1.0.0GHSA-j8qm-q4hg-mvr72026-09-snap-queueSame class as snap-queue
poly-check-b1.0.0GHSA-3324-42r3-w6mm2026-09-snap-queueSame class
kerokwis (pypi)<=99GHSA-9fqg-jm66-pjqfGENERIC-standard-pypi-install-pentestsetup.py-override telemetry probe
kerokwis (rubygems)99GHSA-mh78-3v9h-gh6j(rubygems republish)Cross-ecosystem republish under same name

auclean is the standout - a real cloud-credential infostealer with distinct campaign attribution. snap-queue/crypto-trader-py/poly-check-b share a broken-delivery footprint (missing payload) but the intent is unambiguous. kerokwis cross-ecosystem is unusual and worth monitoring for future drops.

Cluster J - Org-internal dep-confusion cluster (single-day sweep)

Targets by scope/name lookalike:

  • Tesla Insurance: @tesla-insurance/vinless-quote
  • UOL Brazilian media: uolcs-host-uol-anuncios-fe (continues yesterday's @uol-afiliados/* cluster)
  • Buy-Now-Pay-Later: bnpl-blocks-mobile-bnpl-floating-button, bnpl-blocks-atom-bnpl-search-input
  • Generic "bigops": bigops-products-timeline, bigops-auth-interceptor
  • Agora / 402: agora402-payment-utils
  • Ubiquiti: ubiquiti-agents-link-mcp@0.0.1/0.0.2/0.2.0/0.2.1
  • Cisco: cisco-github-simple@1.0.1 (with confirmed prk15yh0sbkd1305h200c2wv5mbhz7nw.oastify.com Burp Collaborator exfil of /etc/passwd, /etc/hosts, DNS servers, package.json)
  • internallib_v<NNN> enumeration campaign: internallib_v497@1.0.3 (curl-pipe RCE from RFC1918 10.0.5.109, unencrypted HTTP) + internallib_v550 — continuation of the campaign tracked since 2026-08-03 (previous versions catalogued: _v514, _v524, _v568, _v688, _v756, _v902, _v949, others)
  • Generic -sdk/-utils: devplatform-sdk, take-home-caller-id
  • n8n workflow nodes: n8n-nodes-healthmon, n8n-nodes-metricsagent, n8n-nodes-data-transformer-utils
  • Ethereum library: evm-validation@1.0.0-1.0.4 (1.0.0/1.0.1 from 2024-09-15 - long-standing name squat quarantined only now)

Cluster K - Bulk/random-name quarantines

~60 npm packages with random-string or auto-generated names, quarantined in the 2026-09-22/23 window. CWE-506 boilerplate advisories; per-package payload not disclosed. Coordinated bot-published typosquat activity is likely, but without per-package IOC we cannot cluster them further. Notable named-lure entries in this batch:

  • dbconnectify - previously named as the chai-tracker C2 dependency in the 2026-08-10 sweep; today's quarantine elevates it to first-class tracked malware
  • @httttt/mcp-npx-fetch-1 + @httttt/mcp-demo - MCP-namespace lookalike, httttt scope
  • @test1230504/* - three packages under a shared test scope with sentinel 1.0.0 from 2026-07-28 late-catch
  • z-deno-truth-* - three packages under a Deno-lookalike name pattern
  • @mikudeveloper/baileys - WhatsApp clone impersonation

Cluster L - Pentest/CTF/research artefacts

cloushaar-poc-exfil-91827@0.0.1 pip (GHSA-6wmc-3vvj-9j5f, campaign GENERIC-standard-pypi-install-pentest) - self-labelled POC; exfiltrates IPs and usernames on install; PROBABLY_PENTEST classification. Non-hostile framing but the exfiltration is real.

Also: additional GHSA numbers were reissued against packages already catalogued in the 2026-09-22 sweep (@uol-afiliados/affiliated-config-lib GHSA-mx57-mmpv-mwjr, @uh-platform/domain-widget GHSA-c842-qvgg-5vpf, @uh-platform/cloud GHSA-xrhc-2pph-j3f7, @asdfaskdjfksadhfkasf/nadaver2 GHSA-xxcj-347q-8rrr). These are secondary advisory records for the same underlying publish and do not represent new drops.

Cross-operator patterns worth flagging

  1. The oob.algamil7x.xyz operator is on day 6 - nine consecutive days with a fresh internal-lookalike scope each day but the same DNS zone, code style, and primitive. This is now the longest-running single-operator campaign in the DependencyWatch corpus for 2026 Q3.
  2. *The `hardhat- axios-loader RCE wave is a two-day event** and the operator is doing late-quarantine catch-up on Jul publishes (hardhat-hold@2.0.1 from Jul 24, hardhat-core@1.0.0 from May 13). Expect more hardhat-*` names to surface as npm review works through the backlog.
  3. *The `chai-/pino/jsonspack.com family** is now a three-week arc (chai-tracker Aug 10, chai-testing Sep 21, chai-as-viem/chai-logger Sep 22). Same author fingerprint, same axios-loader primitive with pino` cover files, new lure name each drop.
  4. npmjs.it.com as a typosquat of the registry itself is a new escalation vector. Prior families used generic C2 domains; imitating the registry domain and hosting on the .it TLD compounds the misdirection.
  5. Cross-ecosystem republishes are appearing more often - kerokwis (pypi + rubygems), the @baanx/* and @user-services/* internal-scope operator (still npm-only for now but the pattern of testing new scopes daily is similar in spirit).
  6. Late batch quarantines continue to compress - @wizloft/harness-* (15 packages in 4 minutes), envforge/envparse (6 packages in 90 seconds). npm review is working through a real backlog, and a lockfile hit today may correspond to exposure that started weeks or months ago.

Registry state

All packages in Clusters A, D, E, K are npm-quarantined (replaced with 0.0.1-security holding package). Cluster B (hardhat-hold) is quarantined; Cluster C's chai-as-viem is quarantined; Cluster F's oracle-redis may still be live at publish time (advisory published Sep 22, no npm takedown timestamp seen). Cluster G (@vitemirrorte/element-plus-vite-cli@2.9.1) is npm-quarantined but the C2 domain npmjs.it.com remains operator-controlled. Cluster H (@gsutevil/hta-stage) is npm-quarantined but the anonymous MSI-hosting endpoints remain live.

Durable network-edge mitigations: egress blocks on oob.algamil7x.xyz, ipcheck-hashed.vercel.app, jsonspack.com, npmjs.it.com, *.oastify.com (or the specific prk15yh0sbkd1305h200c2wv5mbhz7nw subdomain), unencrypted HTTP to 10.0.5.109, and unexpected Cloudflare Workers subdomains.

Discovery credits

GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector, ESTsecurity, kam193/bad-packages, jaschadub/compromised-packages-check. Per-package IOC details drawn from GHSA and OpenSSF advisory bodies published between 2026-09-22 12:00 UTC and 2026-09-23 12:00 UTC.

Affected packages (76)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • *Cluster A - npm `@tvg-mar/ + @user-services/web-components oob.algamil7x.xyz DNS-OOB (day 6 of the operator)**: @tvg-mar/tvg-promos-atomic-ui@9.9.10 (GHSA-fvh3-76xv-7978, MAL-2026-16415), @tvg-mar/promos-context@9.9.10 (GHSA-gmpx-wq8f-4q86), @tvg-mar/promos-gtm@9.9.10 (GHSA-4mmr-x347-r6gv), @tvg-mar/storyblok-bridge@9.9.10 (GHSA-r788-p8wq-7672), @tvg-mar/utils@9.9.10 (GHSA-g5mj-6q8x-7cj6), plus @user-services/web-components@9.9.10 (GHSA-6q28-qx7w-pv4x). All published in the 2026-09-22/23 window with the exact same primitive as days 1-5 (@tink, @shared-web/@shared-runtime/@insiderintelligence, @baanx/solana-lib, @baanx/abis/blockchain-config): scripts.install: node index.js loads a runtime/support/telemetry/probe/impl.js module that reads os.userInfo().username, os.hostname(), and process.cwd() basename via module.constructor._load (indirect Node builtin resolution to defeat static analysis), joins them with a timestamp and a per-package prefix, and issues a dns.resolve4 on <prefix>-<user>-<host>-<cwd>.<ts>.oob.algamil7x.xyz. Sibling probe/*.js files carry String.fromCharCode` hex-array obfuscation of the destination domain. Same operator, same DNS zone, same code style - now spanning nine consecutive days. Amazon Inspector flagged each within minutes of publish
  • Cluster B - npm hardhat-hold axios-loader RCE typosquat wave extension: hardhat-hold@2.0.1 (2026-07-24), 2.21.0 (2026-07-31), name-quarantined by npm 2026-09-23 00:09 UTC. Fourth hardhat-* in the Ethereum-toolchain typosquat wave that surfaced yesterday (hardhat-base, hardhat-core, hardhat-devkit were catalogued in the 2026-09-22 sweep). Late-catch of packages that sat on the registry for two months before npm review picked them up. Payload class matches the family: detached child process + base64-decoded remote URL + axios POST + Function.constructor eval of the response body. Any lockfile with a hit was exposed for ~2 months
  • *Cluster C - npm `chai- axios-loader RCE family extension**: chai-as-viem (GHSA-88fm-v2m3-mx8x, quarantined 2026-09-22 18:20 UTC) and chai-logger@3.0.2 (GHSA-fv5h-7hj3-xq5r) both extend the chai-family axios-loader RCE class first catalogued as chai-testing in the 2026-09-21 sweep and continued through chai-as-persisted/chai-tracker in prior batches. GHSA analysis on chai-logger confirms the family signature: ~4 MB heavily-encoded module executed at import, pino logger source files as camouflage cover, axios declared only inside the obfuscated code, author field references jsonspack.com. chai-as-viem is the register-continuation drop (Viem is a modern Ethereum client library - the name lures developers writing Ethereum test suites). Note: chai-tracker versions 1.1.0-1.1.3 and 1.2.1` were already catalogued in the 2026-08-10 sweep; the 2026-09-23 npm-side quarantine confirms npm has now taken over the name (this sweep does not re-add the package)
  • Cluster D - npm envforge/envparse 6-package coordinated typosquat batch: envparse2 (GHSA-q747-c2cv-gfhj), envparse3 (GHSA-vq77-3r62-c2cx), envforge2 (GHSA-h8xg-3hfp-rx6q), envforge3 (GHSA-7chm-5cxc-2wx2), better-envforge (GHSA-3h54-43fv-m822), node-env-buffer (GHSA-2g29-f3qp-c7gf). All six quarantined by npm in a ~90-second window on 2026-09-22 18:21 UTC (single-batch sweep). All target the .env/dotenv ecosystem with plausibly-legitimate names (envparse and envforge look like variants of envparse/env-forge). GHSA advisories carry the generic CWE-506 boilerplate; the specific per-package payload is not disclosed but the coordinated multi-name naming pattern and simultaneous npm review action is a classic operator-batched typosquat drop targeting .env-loading libraries
  • *Cluster E - npm `@wizloft/harness- 15-package batch quarantine (Aug-Sep buildup)**: @wizloft/harness (GHSA-hv3x-6r5c-g4cp), @wizloft/harness-cli-adapter (GHSA-hmmw-27v2-3qc8), @wizloft/harness-file-providers (GHSA-2jrv-g43f-qm7f), @wizloft/harness-plugin-repository-files (GHSA-p4gf-f4rj-hfh8), @wizloft/harness-project (GHSA-xj44-gx57-mm59), @wizloft/harness-commands (GHSA-cv26-mq7q-h5hq), @wizloft/harness-authority (GHSA-8h24-fp89-4cw3), @wizloft/harness-evidence (GHSA-mjfj-x5qx-p7v8), @wizloft/harness-plugin-file-events (GHSA-6866-wx9h-j2rh), @wizloft/harness-plugin-file-memory (GHSA-64w5-qg43-54g7), @wizloft/harness-plugin-memory-context (GHSA-r4qq-8p58-gfpv), @wizloft/harness-validation (GHSA-7g98-grc6-6xjh), @wizloft/harness-context (GHSA-wjhv-xmmw-qqf9), @wizloft/harness-memory (GHSA-3mjw-625p-wvhf), @wizloft/harness-kernel (GHSA-9f63-qfxp-2726). All 15 quarantined by npm in a 4-minute window on 2026-09-23 00:20 UTC. Alpha and beta versions had been publishing since 2026-08-17 through 2026-09-06 - a ~5-week buildup before batch quarantine. CWE-506 boilerplate advisories; specific payload not disclosed. Coordinated multi-package @wizloft/harness-*` naming targets a testing/CI harness scope
  • Cluster F - npm transitive-dependency trojan (oracle-redis + turbo-ws): oracle-redis@5.11.3 (GHSA-8m7m-r8mw-mvq2) impersonates ioredis with copied README and repo URL; declares unused runtime dependencies redis-type-intel@^1.10.5 and pino-ulid@^2.12.2 whose sole purpose is to fire their own lifecycle scripts during npm install. turbo-ws@1.0.0 (GHSA-49rw-43cc-8cmh) declares zero dependencies in its README but its package.json hides a transitive dependency node-net-pool pinned to an HTTPS tarball on an unrelated GitHub account; the tarball is fetched at install-time with no integrity check and its postinstall runs immediately. Both use the same architectural class as the 2026-09-22 bytepack-probe-a7x3 (Cluster H of that sweep) - malicious code injected via the dependency graph rather than in the target package itself. --ignore-scripts blocks these
  • Cluster G - npm @vitemirrorte/element-plus-vite-cli@2.9.1 mall4cloud-react-targeted full-featured Node RAT (highest-severity single package of the sweep): MAL-2026-16401, GHSA-j7hr-ff2j-rgv6. Masquerades as an Element Plus + Vite CLI helper. On install, deploys a persistent agent to ~/.gradle/caches/ (Gradle cache is on the developer PATH, survives npm re-installs, and is rarely audited). Agent registers to https://npmjs.it.com (a typosquat of npmjs.com built to inherit search-time legitimacy) with hostname, OS username, os.type()/os.release(), and a persistent agent_id. Full remote-control protocol: exec opcode runs arbitrary shell commands; fs.readFileSync + exfil opcodes read arbitrary files; upload/delete/move opcodes; process and directory listings. Activation is gated on workspace name mall4cloud-react (an open-source Chinese e-commerce reference project) via fingerprinting - the RAT stays dormant on other checkouts to avoid detection, then wakes only when the operator's targets clone the intended repo. Any developer who cloned a mall4cloud-react fork and ran npm install on 2026-09-22 or 2026-09-23 has an active RAT with ~/.gradle/caches/ persistence
  • Cluster H - npm @gsutevil/hta-stage Windows HTA/WSH MSI loader: @gsutevil/hta-stage@>=1.62.0 (GHSA-95xp-29r3-v466). Windows-only staging payload: disables Windows Script Host anti-malware scanning via multiple registry-modification methods, collects computer name and username and beacons to attacker infrastructure, terminates Python processes and removes prior implants (cleanup), silently downloads and executes MSI packages from attacker-controlled servers, reconstructs all sensitive identifiers (ScriptControl, WScript.Shell, .exe, MSI URLs) at runtime from String.fromCharCode byte arrays to defeat static AV signatures. Same TTP class as the Roblox-TS Windows RAT family tracked in prior sweeps but with the MSI-download escalation. Amazon Inspector flagged
  • Cluster I - pip infostealer / campaigns: auclean@0.4.2/0.4.3/0.4.4 (GHSA-v257-9gjr-rv2j, campaign 2026-09-auclean) is a real cloud-credential infostealer - fingerprints host env, network scans, searches for specific files, harvests cloud provider credentials (AWS/GCP/Azure tokens implied by "cloud credentials"), then exfiltrates. snap-queue@1.0.0 (GHSA-3v8f-m5rm-8mv3), crypto-trader-py@1.0.0 (GHSA-j8qm-q4hg-mvr7), and poly-check-b@1.0.0 (GHSA-3324-42r3-w6mm) form the 2026-09-snap-queue campaign - all three override setup.py's install command to run malicious code; the payload file was missing from the analyzed samples (operator forgot to include it) but the intent and delivery mechanism are unambiguous. kerokwis publishes as both pypi (<=99, GHSA-9fqg-jm66-pjqf, GENERIC-standard-pypi-install-pentest campaign) and rubygems (99, GHSA-mh78-3v9h-gh6j) - setup.py-override telemetry probe on install; the cross-ecosystem republish under identical names is unusual and suggests operator experimentation with rubygems as a secondary channel
  • Cluster J - npm org-internal dep-confusion cluster (single-day sweep of internal-scope squats): @tesla-insurance/vinless-quote (GHSA-p853-37gq-hxpj, Tesla Insurance impersonation), devplatform-sdk (GHSA-24m2-6frm-vxj3), uolcs-host-uol-anuncios-fe (GHSA-p4vr-mx6g-r574, UOL Brazilian media continuation from yesterday's @uol-afiliados cluster), bnpl-blocks-mobile-bnpl-floating-button (GHSA-vrh4-rf6w-3256) + bnpl-blocks-atom-bnpl-search-input (GHSA-pvq7-rm52-m5g7) (Buy-Now-Pay-Later block-component impersonation), bigops-products-timeline (GHSA-9f9c-qwvh-f45q) + bigops-auth-interceptor (GHSA-7pp9-3qqc-vc84), agora402-payment-utils (GHSA-pvr5-m9hx-xxfr), ubiquiti-agents-link-mcp@0.0.1/0.0.2/0.2.0/0.2.1 (GHSA-f2wc-4v37-6f5h, hash bb2bd11478a4b45a05adf8ac3c9b4ddeb169297b9c280916a25eccd4dd827922, Ubiquiti networking impersonation), internallib_v497@1.0.3 (GHSA-m9ww-2r6q-x632, curl-pipe RCE from RFC1918 10.0.5.109) + internallib_v550 (GHSA-vc8f-vp28-j8g3) (continuation of the internallib_v<NNN> sequential-enumeration campaign tracked since 2026-08-03), cisco-github-simple@1.0.1 (GHSA-2ph4-jf5x-92pp, Cisco impersonation with prk15yh0sbkd1305h200c2wv5mbhz7nw.oastify.com Burp Collaborator OOB exfil of hostname, username, home dir, DNS servers, /etc/passwd, /etc/hosts, package.json), take-home-caller-id (GHSA-2g3j-m32f-cc29), n8n-nodes-healthmon + n8n-nodes-metricsagent + n8n-nodes-data-transformer-utils (n8n workflow node impersonators), and evm-validation@1.0.0-1.0.4 (GHSA-gvxq-2rq2-f7x6, Ethereum library impersonation, 1.0.0/1.0.1 from 2024-09-15 - long-standing name squat)
  • Cluster K - npm bulk/random-name quarantines (payload not disclosed in GHSA body; treat as install-time compromise pending IOC): z-deno-truth-va499w/ya1t4m/bwhlsz (Deno lookalike, 3 pkgs), @test1230504/probe-7f3k2m-utils/string-format-helper/test-publish-verify (3 pkgs; @test1230504 scope with sentinel version 1.0.0 from 2026-07-28 late-catch), @httttt/mcp-npx-fetch-1 + @httttt/mcp-demo (MCP-namespace lookalike), plus ~60 random-name npm packages (mbxcnsuwgs1, mn4xcouzvhus, xsjukcnv8low26, vxhjkseuiaqkb, mob4zchvuine, mobiwaefhxc3, tuxcmdfhjkw, m3fdfocdoewn, mjsdqwocvn, testdgdbcsd, tib2jcvowuyma, kamafhbnowct, m2fcsfyjkuxb, tesgfvbncsdbcv, mn2adskhweox, ndmxchdjxn2, ndmfguyhoxc3, ndmushdkeqe, mn3sadkoiewu, skxcmwuncbg2, tibcwmpoeafh, caphsmgiwy, luftzxyuiwgbgsp, cloudndmcedu, ndmcmsujey, ndmckauxuoincv, ndmcjcxiebysfdb, luftmvfiwgxydes, lufxchwmxwyps, fdhcxvnwhjiofv, kambxjowhdsgyw, tldriver, tlxbnhd, mxdriver, efhthrthrthregerht, moudeva, moidevl, catqrcodeconverter, catplatebarcodeparser, dbconnectify, iso-datetime-core, semver-bump-io, debounce-throttle-base, prettier-lint-lenz, solo-async-pipe, webp-https-errors, better-md, some-tool-package, subapp-pkg-util, eslint-config-compact-utils, eslint-plugin-i18n-shreddit, my-company-device, nodetokyo, @mr-supun-fernando/supunmd-bail, action-slack-message-root, sysverify, tailwind-form-styles, noverojava, @mikudeveloper/baileys, anhn-cli, no-fun (rubygems)). Note: dbconnectify was previously named as the chai-tracker C2 dependency in the 2026-08-10 sweep but not tracked as a package on its own - today's quarantine finally elevates it to first-class tracked malware
  • Cluster L - Pentest/CTF/research artefacts (real payloads, non-hostile framing): cloushaar-poc-exfil-91827@0.0.1 pip (GHSA-6wmc-3vvj-9j5f, campaign GENERIC-standard-pypi-install-pentest, PROBABLY_PENTEST classification) - setup.py-override that exfiltrates IPs + usernames; self-labelled POC. Also on the 2026-09-22 side: additional GHSA numbers reissued against packages already catalogued in the 2026-09-22 sweep (@uol-afiliados/affiliated-config-lib GHSA-mx57-mmpv-mwjr, @uh-platform/domain-widget GHSA-c842-qvgg-5vpf, @uh-platform/cloud GHSA-xrhc-2pph-j3f7, @asdfaskdjfksadhfkasf/nadaver2 GHSA-xxcj-347q-8rrr) - these are secondary advisory records for the same underlying package publish and do not represent new drops

What to do

  1. 1Grep every package-lock.json, yarn.lock, pnpm-lock.yaml, package.json, requirements.txt, Pipfile.lock, and poetry.lock in your org for every package name in Clusters A through L. Uninstall on hit, wipe node_modules/.venv, delete the lockfile, rebuild against a clean cache. Clusters A, B, C, F, G, H, I, and Cluster J (subset) include real disclosed payloads (DNS-OOB, axios-loader RCE, transitive-dependency trojans, full RAT with mall4cloud-react gate, Windows HTA/WSH MSI loader, cloud-credential infostealer, curl-pipe RCE, Burp Collaborator OOB) - a hit on any of those is a compromise, not a warning
  2. 2*For Cluster A (`@tvg-mar/ + @user-services/web-components algamil7x day 6)**: block oob.algamil7x.xyz at your resolver (same operator zone as the 2026-09-18 through 2026-09-22 clusters - now spanning nine days). Every new day this operator publishes under a fresh internal-lookalike scope name, so pin-by-scope is a losing game - the durable mitigation is resolver-level DNS blocking of algamil7x.xyz`. Any host that installed the packages DNS-resolved a label carrying hostname/username/cwd - rotate credentials accessible from that host
  3. 3For Cluster B (hardhat-hold continuation): block ipcheck-hashed.vercel.app at CI egress and any similar Vercel-hosted axios-loader endpoint (see 2026-09-22 sweep for the exact URL path). Uninstall any hardhat-* package that is not @nomicfoundation/hardhat-* and rotate every credential visible to the parent Node process. Packages were live for ~2 months before quarantine so a hit implies extended exposure
  4. 4*For Cluster C (`chai- axios-loader family)**: block jsonspack.com at CI egress, uninstall on hit. --ignore-scripts does NOT block this family - the RCE fires when the exported chai plugin is loaded via chai.use() or imported. Any dev environment that ran a chai-based test suite in the exposure window is potentially compromised. chai-as-viem` in particular is a plausible drop for developers writing Ethereum test suites with Viem
  5. 5For Cluster D (envforge/envparse batch): audit any .env-loading library your projects import. If your package.json says envparse, env-parse, envforge, or env-forge, verify the exact spelling against the legitimate package registry - any envparse2/envparse3/envforge2/envforge3/better-envforge/node-env-buffer reference is a compromise indicator
  6. 6*For Cluster E (`@wizloft/harness- 15-package batch)**: uninstall on hit. Packages were live for ~5 weeks (Aug 17 - Sep 6 publish window) so a hit implies extended exposure. If your org maintains an internal @wizloft` scope for a CI harness, pin it to your private registry
  7. 7For Cluster F (transitive-dependency trojan): enforce --ignore-scripts at the CI runner level; audit package.json for any dependency declared as an HTTPS-tarball URL rather than a registry version ("pkg": "https://..." in the deps map is a red flag). If you meant ioredis, verify the exact spelling; oracle-redis and turbo-ws should not appear in any modern Redis/WebSocket workflow
  8. 8For Cluster G (@vitemirrorte/element-plus-vite-cli mall4cloud-react RAT): block npmjs.it.com at your resolver AND at your web proxy - this is a typosquat of npmjs.com and no legitimate traffic should reach it. If your org has any developer or CI runner that touched a mall4cloud-react fork in the last 48h, assume that workstation is fully compromised: image it, do not attempt to clean in place. Rotate every credential the RAT could have reached (SSH keys, cloud tokens, browser sessions, IDE tokens, git credentials). Delete ~/.gradle/caches/ on remediated hosts and rebuild the Gradle cache from a clean source
  9. 9For Cluster H (@gsutevil/hta-stage Windows HTA/WSH loader): uninstall on hit. Windows-only impact - Linux/macOS developers are not affected. Audit Windows workstations that touched the package for: Windows Script Host registry keys modified (HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings), MSI installations from unfamiliar sources in the last week (WMI query Win32_Product), Python-process termination events in Windows event logs, and any HTA/WSH launcher persistence
  10. 10For Cluster I (pip auclean + snap-queue campaign + kerokwis): uninstall on hit. For auclean, treat any workstation that installed it as compromised - the infostealer targets cloud credentials specifically (AWS/GCP/Azure). Rotate cloud provider access keys, IAM roles, session tokens; audit CloudTrail / Cloud Audit Logs / Activity Logs for the last 72h for unfamiliar access. For snap-queue/crypto-trader-py/poly-check-b, the payload was missing from the analyzed samples but the delivery mechanism is fully wired - assume future republishes will carry a live payload. For kerokwis, the cross-ecosystem republish (pypi + rubygems under the same name) is unusual; monitor for other cross-ecosystem drops from the same operator
  11. 11For Cluster J (org-internal dep-confusion): pin the internal-looking names (@tesla-insurance, @ubiquiti-agents-*, @n8n-nodes-*, internallib_*, @cisco-*, @bnpl-*, @bigops-*, @agora402-*, @uolcs-*) to your private registry with .npmrc. Block *.oastify.com at CI egress (specifically prk15yh0sbkd1305h200c2wv5mbhz7nw.oastify.com for cisco-github-simple). For internallib_v497 / internallib_v550, block outbound HTTP to 10.0.5.109 at your CI network egress - RFC1918 target means it only fires from inside the operator's intended network, which is a strong indication of a targeted internal-registry attack. If your org runs any internallib_v<NNN> internal scope, the campaign is enumerating your version numbers
  12. 12For Cluster K (bulk/random-name quarantines): uninstall on hit. dbconnectify in particular is worth grepping for retrospectively - it was named as the chai-tracker C2 dependency in Aug and any lockfile that pulled in chai-tracker between 2026-08-10 and 2026-09-23 likely also has dbconnectify transitive. Audit for any package that includes dbconnectify as a runtime dependency
  13. 13For Cluster L (pentest/CTF artefacts): uninstall on hit. cloushaar-poc-exfil-91827 is self-labelled research POC but the exfiltration is real; treat as a leak of hostname and username. For the additional GHSA reissues on already-catalogued 2026-09-22 packages, no new action needed - remediation from yesterday's sweep applies
  14. 14For every npm install in CI, prefer --ignore-scripts and enforce it at the runner level (note it does NOT block Cluster C - chai-family RCE fires at import, not on install script). Layer with egress denylists on oob.algamil7x.xyz, ipcheck-hashed.vercel.app, jsonspack.com, npmjs.it.com, *.oastify.com, 10.0.5.109, and unexpected Cloudflare Workers subdomains. Extend the pin-lists from prior sweeps with @tvg-mar/*, @user-services/*, @wizloft/*, @tesla-insurance/*, @httttt/*, @vitemirrorte/*, @gsutevil/*, @test1230504/*, envparse2, envparse3, envforge2, envforge3, better-envforge, node-env-buffer, oracle-redis, turbo-ws, hardhat-hold, evm-validation, chai-as-viem, chai-logger, internallib_v497, internallib_v550, cisco-github-simple, ubiquiti-agents-link-mcp, agora402-payment-utils, devplatform-sdk, uolcs-host-uol-anuncios-fe, bnpl-blocks-*, bigops-*, n8n-nodes-*, take-home-caller-id, dbconnectify, and pip auclean / snap-queue / crypto-trader-py / poly-check-b / kerokwis / cloushaar-poc-exfil-91827

References

multi-2026-09-23-ghsa-malware-sweep