Feed
HighAdvisory sweepPublished 25 Sept 202624 packages · 58 versions

GitHub Advisory malware sweep - 2026-09-24 (late) + 2026-09-25 (npm `@nf-addons/am-global-header` + `@osl-design/react` `oob.algamil7x.xyz` DNS-OOB day-7 late-adds missed by yesterday`s sweep; `n8n-nodes-moonlet-helpers`/`-utils`/`n8n-nodes-flowstats` `mkicom.com` fake `.well-known/pki-validation/` dropper family with `104.21.3.16` bare-IP + magic-key RCE; `secure-env3` + `better-dotenv3` JPEG-APP13/APP14 hidden VBS/PowerShell Windows dotenv typosquat dropper family; `agency-test-exercise` + `agency-testts` `wscript.exe 4444.vbs` AES+ChaCha20 Windows dropper; `chromatitle` + `chromatitle-js` ANSI-color-lure obfuscated fetch-and-execute; `wallet-connect-adapter` Windows XOR-encrypted Python dropper; `simple-date-formatter-new-11/13/14/15` continuation of the `124.221.154.135` SSH-key + `oast.fun` campaign (13/14/15 new C2 hosts); `aliftech-ui` + `@birbalo/aliftech-ui` shared-`webhook.site` dep-confusion siblings; `@alphaspace/core` Yahoo-internal dep-confusion Pipedream + istio/yahoo DNS recon; `eslint-config-compact-base` AWS API Gateway CI recon; `c2-client` postinstall command channel; pip `prosocks` proxy-network hijack campaign + `my-private-pkg` + `vercel-runtime-python` Vercel dep-confusion pentests)

Summary

GHSA 2026-09-24 (late) + 2026-09-25: ~24 new npm advisories + 3 pip. Two oob.algamil7x.xyz day-7 late-adds yesterdays sweep missed (@nf-addons/am-global-header, @osl-design/react). New n8n-nodes-* mkicom.com dropper family. secure-env3/better-dotenv3 JPEG-hidden Windows dropper family. simple-date-formatter-new-11/13/14/15 extend the 124.221.154.135 campaign. @alphaspace/core` targets Yahoo internal builds.

dependency-confusiontyposquatdns-exfiltrationcredential-theftobfuscationci-cd-compromiseinfostealer
Incident type
Advisory sweep. A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · Amazon Inspector · Safedep · kam193/bad-packages · jaschadub/compromised-packages-check
Also known as
2026-09-25 GHSA npm sweep · @nf-addons + @osl-design algamil7x.xyz day-7 late-adds · n8n-nodes-* mkicom.com dropper family · secure-env3 + better-dotenv3 JPEG-hidden dotenv dropper family · agency-test-exercise + agency-testts 4444.vbs AES dropper · chromatitle + chromatitle-js obfuscated fetch-and-execute · wallet-connect-adapter Windows Python dropper · simple-date-formatter-new-11/13/14/15 124.221.154.135 continuation · @alphaspace/core Yahoo internal dep-confusion · prosocks proxy-network hijack (2026-09-prosocks) · my-private-pkg + vercel-runtime-python Vercel dep-confusion
Ecosystems
npmPyPI
Packages tracked
24

What happened

Between roughly 2026-09-24 12:00 UTC and 2026-09-25 12:00 UTC, GitHub Advisory Database (plus the OpenSSF malicious-packages bulk export, Amazon Inspectors IN-MAL feed, and Safedeps compromised-package tracker) published approximately 24 new npm malware advisories and 3 new pip advisories. The window is dominated by two oob.algamil7x.xyz day-7 late-adds that yesterdays sweep missed, a new mkicom.com n8n-nodes- dropper family, a Windows JPEG-hidden VBS/PowerShell dotenv-typosquat family, a simple-date-formatter-new- continuation of the 124.221.154.135 SSH-key campaign, and one Yahoo-internal dep-confusion attempt (@alphaspace/core`).

Cluster A - @nf-addons/am-global-header + @osl-design/react oob.algamil7x.xyz day-7 late-adds (MISSED by yesterday`s sweep)

PackageVersionGHSAPrefix in DNS label
@nf-addons/am-global-header9.9.10GHSA-hj7v-p563-fffq(not published)
@osl-design/react9.9.10GHSA-qx4v-776h-xcpwosldr

Both match the exact algamil7x day-7 primitive:

  • os.userInfo().username + os.hostname() + process.cwd() concatenated into a DNS label
  • Destination oob.algamil7x.xyz stored as a hex/char-code array in a lib/*.js module
  • Destination reconstructed at runtime via String.fromCharCode
  • os, dns modules loaded via module.constructor._load rather than literal require() to defeat static analysis
  • Fires both at install (scripts.install) and on require(), wrapped in a swallowed try/catch

This confirms the operator on day 7 (2026-09-24) using two more scoped-lookalike names, extending the campaign from the multi-2026-09-24 sweep Cluster A (which caught @baanx/common, @baanx/domain, @insiderintelligence/componentlibrary but not these two).

Day-1 through day-7 recap:

  • Day 1 (2026-09-18): @tink/tink-link-core
  • Day 2 (2026-09-19): @insiderintelligence/googleadmanager
  • Day 3 (2026-09-20): @insiderintelligence/* variants
  • Day 4 (2026-09-21): @baanx/solana-lib etc
  • Day 5 (2026-09-22): @baanx/abis, @baanx/blockchain-config
  • Day 6 (2026-09-23): @tvg-mar/*, @user-services/*
  • Day 7 (2026-09-24): @baanx/common, @baanx/domain, @insiderintelligence/componentlibrary, @nf-addons/am-global-header, @osl-design/react

No fresh algamil7x-branded advisories have appeared in the 2026-09-25 batch as of publication. Either the operator paused, day-8 has not yet propagated to the trackers, or day-7`s late additions were the tail of the campaign.

Cluster B - npm n8n-nodes-moonlet-helpers/-utils + n8n-nodes-flowstats mkicom.com dropper family (new operator)

PackageVersionGHSATriggerPayload path
n8n-nodes-moonlet-helpers1.0.0/1.0.4GHSA-hh4f-fhfw-7vgwpostinstallmkicom.com/.well-known/pki-validation/ct_pn8 -> /tmp/.np
n8n-nodes-moonlet-utils1.0.0GHSA-f77h-w3rc-2c74postinstallmkicom.com/.well-known/pki-validation/ct_dn8 -> /tmp/.nc
n8n-nodes-flowstats1.0.0GHSA-wm7h-qmp4-782cmodule load + node execute104.21.3.16 (Host: mkicom.com); magic-key RCE via {cmd, k:"kx9p26"}

All three ship an empty stub index.js (module.exports = {} or trivial), doing no legitimate work. The postinstall.js (moonlet-helpers/utils) or module-load hook (flowstats) fetches an opaque binary via HTTPS from mkicom.com (or the bare IP 104.21.3.16 with a spoofed Host header for flowstats), writes it under /tmp/.<letters> with chmod 0755, and executes it detached via a shell + setsid wrapper. Zero hash verification, zero signature, zero version pinning.

The path .well-known/pki-validation/ is chosen to blend with legitimate ACME certificate-transparency traffic - a host-based block is easily bypassed by moving to a new host under the same path convention, so a path-based block is needed too.

n8n-nodes-flowstats adds two additional primitives on top of the shared dropper:

  1. Module-load beacon: on require() the code checks n8n-specific env vars; if any are set, it issues an HTTPS GET to 104.21.3.16 with Host: mkicom.com and executes the returned payload via shell
  2. Magic-key backdoor: the exported n8n nodes execute() accepts {cmd, k} from HTTP request payloads; when k === "kx9p26", cmd is passed to child_process.exec` with a 25-second timeout

This is a fully-usable backdoor aimed at self-hosted n8n workflow-automation deployments - anyone who imported the flowstats node into a webhook-triggered n8n workflow has exposed a child_process.exec gateway to the internet.

Cluster C - JPEG-hidden VBS/PowerShell Windows dotenv-typosquat dropper family

PackageVersionGHSAJPEG segmentNotes
secure-env31.0.1GHSA-w2g5-xcc6-p474APP14 (0xEE)Self-deleting VBS -> wscript.exe -> powershell.exe
better-dotenv31.0.1GHSA-qx8m-mvxg-49m3APP13 (0xED)Internal package.json name is node-env-buffer@2.2.6

Both impersonate the dotenv library. The bundled dist/stest.jpg is a real JPEG with a hidden payload embedded in one of its non-standard APPn marker segments. On module import/require or CLI startup (Windows only), the code:

  1. Reads dist/stest.jpg
  2. Parses the APP13 or APP14 segment to extract the encoded UTF-8 payload
  3. Writes a self-deleting .vbs wrapper to os.tmpdir()
  4. Launches wscript.exe <path>.vbs, which chains to powershell.exe with encoded commands

Executable names and PowerShell switches are assembled at runtime by joining split character arrays to evade static string scanners. The fact that better-dotenv3's internal package.json declares a different name (node-env-buffer@2.2.6) suggests the same JPEG-loader stager is being redistributed under a rotating set of dotenv-variant published names - expect more *-dotenv* and *-env* names to appear.

Cluster D - agency-test-exercise + agency-testts wscript.exe 4444.vbs AES+ChaCha20 Windows dropper

agency-test-exercise@1.0.2 (GHSA-qwj9-hfhg-j6vh) and agency-testts@1.0.0 (GHSA-75mh-8gwp-9cvf). Both declare postinstall: wscript.exe 4444.vbs in package.json. The bundled 4444.vbs is ~660-674KB and holds a base64 string array (~660 entries) that is reassembled and decrypted through layered AES-256-CBC + ChaCha20-IETF with embedded keys (stateFKK, manifestGCP). The decrypted payload lands in %TEMP% as a random .dat file and is passed to PowerShell for in-memory execution + process hollowing. Additional Windows-API-call-name obfuscation via XOR-encoded strings.

The fraudulent README self-labels as a "Device Telemetry Aggregator". Amazon Inspector hash: 43eddaf152e2aa60b9f823513a2d9b11fc424a5cff4bb3c031f6823a48dc2f4e (agency-test-exercise).

Cluster E - chromatitle + chromatitle-js obfuscated fetch-and-execute

chromatitle@1.0.0 (GHSA-7pgp-qm32-53rp) and chromatitle-js@1.0.0 (GHSA-93mr-5j8f-6p3w). Advertised as ANSI-color/title formatters. The main entry unconditionally executes a ~51KB javascript-obfuscator payload:

  • 400-entry rotated string array
  • Hex-escaped identifiers
  • RC4-style decoder
  • Self-defending IIFE that trips on tampering

The decoded code imports https.get, http.get, fs.createWriteStream, child_process.execFile/spawn, then platform-detects Windows/Linux/macOS/FreeBSD/SunOS and branches. --ignore-scripts does NOT block this - the fetch-and-execute fires when the module is required, not when it is installed.

Source hash for chromatitle: 793cf7eb2b4de9c41e229fc89c393e38f05141991762f69f310e1397fa464f9c.

Cluster F - wallet-connect-adapter@1.4.2 Windows XOR-encrypted Python dropper

(GHSA-39rm-rv2w-366r). postinstall script runs a loader that decodes an embedded ~8KB blob, XOR-decrypts with a hardcoded 32-byte key, silently pip install requests if missing, then executes the decrypted Python payload as a hidden detached child process. Package os field is restricted to ["win32"] so the malware only fires on Windows installers. The stub index.js is non-functional cover.

Cluster G - simple-date-formatter-new-11/13/14/15 (continuation of the 124.221.154.135 + oast.fun campaign since 2026-08-03)

PackageVersionGHSAC2
simple-date-formatter-new-111.0.0GHSA-2v58-3f75-j4jv124.221.154.135:443/post + pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun
simple-date-formatter-new-131.0.0GHSA-539g-4gx9-g555Baidu SSRF bsrc-ssrf.n.baidu-int.com/6395292252 -> pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun/bsrc
simple-date-formatter-new-141.0.0GHSA-7r88-5m7v-8m5w9e954818.log.dnslogs.dpdns.org + 124.221.154.135
simple-date-formatter-new-151.0.0GHSA-fj2x-7537-68xm124.221.154.135:443/post (placeholder YOUR_BURP_SERVER for cloud-metadata data)

All four masquerade as three-line date-formatting stubs. The postinstall or on-import code enumerates cloud-provider instance-metadata endpoints (Alibaba 100.100.100.200/metadata.tencentyun.com, AWS 169.254.169.254, Tencent 169.254.0.23), reads SSH keys from ~/.ssh, and exfiltrates via HTTPS POST to 124.221.154.135:443/post (same C2 IP as -new-9/-new-10 catalogued 2026-08-10 on port :4444 - port has moved, IP has not).

The -new-13 variant swaps in a Baidu internal SSRF target at bsrc-ssrf.n.baidu-int.com/6395292252, which is a Baidu BSRC bug-bounty SSRF probe target - so this specific package is almost certainly a Baidu-scoped bug-bounty probe not a broad attack - but the other three (-new-11, -new-14, -new-15) carry the same SSH-key exfil primitive as -new-9/-new-10 and should be treated as generalised credential theft.

Campaign scope: the simple-date-formatter-new-<N> naming pattern is now confirmed across -new-1 (2026-08-03), -new-9/-new-10 (2026-08-10), and -new-11/-13/-14/-15 today. An operator publishing sequentially-numbered variants of the same lure name is worth catching with a lockfile-lint regex.

Cluster H - aliftech-ui + @birbalo/aliftech-ui shared-webhook.site dep-confusion siblings

aliftech-ui@99.9.9 (GHSA-648v-rwj3-6j2f) and @birbalo/aliftech-ui@99.9.9 (GHSA-383w-gxv7-cg2f). Both ship a postinstall.js that reads os.hostname() + os.userInfo().username and encodes them in the URL path of an HTTPS request to https://webhook.site/539f8bb9-497a-4104-92f7-f95a77204cc2/. Both packages share the exact same webhook UUID - one operator running two lures.

Aliftech is a real fintech vendor with a legitimate internal aliftech-ui design system. The unscoped aliftech-ui@99.9.9 on the public registry is the classic dep-confusion attention-getter; the @birbalo/-scoped variant is a fallback in case the internal build uses a scope. Amazon Inspector attribution.

Cluster I - @alphaspace/core Yahoo-internal dep-confusion

@alphaspace/core@99.0.0/99.0.1/99.0.2 (GHSA-5qqj-qfpp-jfqw). Preinstall script:

  1. POSTs a JSON payload (hostname, username, Node version, package.json contents, npm registry config) to https://f5778d1d81cc30c39dcdd0da5ca1d49a.m.pipedream.net
  2. DNS-looks up specific Yahoo internal hostnames: istio-system.prod1-gq1.omega.yahoo.com, buildr.corp.yahoo.com, and others
  3. HTTPS-GETs those hosts with NODE_TLS_REJECT_UNAUTHORIZED=0 and captures response bodies to the same collector

Amazon Inspector hash: 42d10ba1427af01794dfb0a6b39a05f969547455e9d86d75f18601b1d035c507.

The specific Yahoo hostnames + @alphaspace scope target the Yahoo/Verizon Media internal build stack. This may be a legitimate bug-bounty engagement (Yahoo runs one) or an attacker probing the same target; either way any lockfile hit is evidence of a real dep-confusion attempt against the Yahoo internal build system.

Cluster J - eslint-config-compact-base AWS API Gateway CI recon

eslint-config-compact-base@1.0.0 (GHSA-ghfm-6qx4-q8p4). On require(), exfils OS platform, hostname, username, arch, Node version, CWD, and the CI env vars CI / RUNNER_NAME / GITHUB_REPOSITORY as query-string params to https://cbrsuo9293.execute-api.us-east-1.amazonaws.com/c (attacker-controlled API Gateway).

Hash dbc01e3a8316b2d4e11b34a9c8cbe1cf5bd2af83a6a70052e40a22b54f13f78b. Fires on module load, so any ESLint run in CI triggers it.

Cluster K - c2-client@1.0.0 postinstall command channel

(GHSA-h7qv-4h6m-4g2x). postinstall: node setup.js runs attacker-controlled code at install time under installer privileges. Advisory body is CWE-506 boilerplate without published IOC or payload analysis. Treat as install-time compromise pending analysis; the unusually candid name c2-client suggests a red-team artefact left published.

Cluster L - pip: prosocks proxy-network hijack + my-private-pkg + vercel-runtime-python Vercel dep-confusion

PackageVersionGHSACampaign
prosocks1.0.0-1.0.9, 1.0.13-1.0.23, 1.0.25-1.0.32GHSA-6v7p-c53r-646f2026-09-prosocks proxy-network hijack
my-private-pkg99.1.1GHSA-v7x9-wx5x-qrppvercel_runtime_python dep-confusion / webhook.site
vercel-runtime-python0.1.0, 99.99.99, 100.99.99, 100.100.99GHSA-fvc2-927p-99h8Vercel dep-confusion (PROBABLY_PENTEST)

prosocks contains embedded code that auto-joins the installer machine to a proxy network - a residential-proxy hijack that turns any developer or CI runner into an unwitting proxy exit node. Persistence + auto-run classification. The ~30-version range is unusual for a probe and consistent with an operator publishing successive builds of a working payload.

my-private-pkg@99.1.1 is a Vercel dep-confusion lure with an install command that collects os.getlogin(), socket.gethostname(), local IP, os.getcwd(), platform.system()/machine() and POSTs to webhook.site/d4d1b01b-708a-40b9-b8c8-187eeecafeed. The package additionally ships a vercel_runtime_python module to mimic Vercel`s Python runtime.

vercel-runtime-python@0.1.0/99.99.99/100.99.99/100.100.99 is the sibling Vercel-runtime-Python dep-confusion probe: setup.py install override + import-time host exfil. Classification PROBABLY_PENTEST.

Both my-private-pkg and vercel-runtime-python target Vercel internal builds.

Cross-operator patterns worth flagging

  1. The oob.algamil7x.xyz operator is now confirmed at nine consecutive days with two late-Sept-24 adds (@nf-addons/am-global-header, @osl-design/react) that yesterday`s sweep missed. No day-8 (Sept 25) additions have appeared yet - the campaign may have paused. Still the longest-running single-operator campaign in the DependencyWatch 2026 Q3 corpus.
  2. Two independent Windows-postinstall PowerShell dropper families land in the same 24-hour window: (i) the JPEG-hidden .vbs -> wscript.exe -> powershell.exe chain (secure-env3, better-dotenv3 - Cluster C), and (ii) the pre-bundled 4444.vbs AES+ChaCha20 chain (agency-test-exercise, agency-testts - Cluster D). Both target Windows exclusively; both use wscript.exe -> PowerShell handoff to defeat AMSI/EDR string-based detection. Expect more of this class as PowerShell-only detections harden.
  3. The mkicom.com operator is new in the corpus - a fake .well-known/pki-validation/ path suggests they know defenders look for anomalous outbound HTTP but not for outbound HTTPS to CT/PKI-shaped paths. The n8n-nodes-flowstats variant additionally ships a usable HTTP magic-key backdoor in what would become an internet-exposed n8n workflow node - a novel primitive not seen in other 2026 Q3 sweep entries.
  4. The 124.221.154.135 SSH-key + .oast.fun operator has now shipped seven public variants under the simple-date-formatter-new-* naming pattern across two months (2026-08-03 -new-1, 2026-08-10 -new-9/-new-10, 2026-09-24 -new-11/-13/-14/-15), with C2 port moving :4444 -> :443 but the IP unchanged. The -new-13 Baidu-SSRF variant is almost certainly a legitimate Baidu BSRC bug-bounty probe; the other six are broad credential theft.
  5. Yahoo-internal dep-confusion is back (@alphaspace/core). Yahoo runs a bug-bounty program that accepts dep-confusion research so this may be legitimate research, but the payload still ships host + build metadata to a public Pipedream endpoint on every install.
  6. Vercel dep-confusion appears in two coordinated pip packages this window (my-private-pkg and vercel-runtime-python) targeting Vercel`s Python runtime name.

Registry state

All packages in Clusters A, C, D, E, F, G, H, I, J, K, L are npm/pip-quarantined (replaced with holding packages). Cluster Bs n8n-nodes-* packages have been yanked but the mkicom.com C2 infrastructure remains active. 124.221.154.135 (Cluster G), f5778d1d81cc30c39dcdd0da5ca1d49a.m.pipedream.net (Cluster I), cbrsuo9293.execute-api.us-east-1.amazonaws.com (Cluster J), webhook.site/539f8bb9-... (Cluster H) and webhook.site/d4d1b01b-...` (Cluster L my-private-pkg) collectors all remain reachable at time of writing.

Discovery credits

GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector, Safedep, kam193/bad-packages, jaschadub/compromised-packages-check. Per-package IOC details drawn from GHSA and OpenSSF advisory bodies published between 2026-09-24 12:00 UTC and 2026-09-25 12:00 UTC.

Affected packages (24)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • Cluster A - npm @nf-addons/am-global-header + @osl-design/react oob.algamil7x.xyz DNS-OOB (day-7 late-adds MISSED by yesterday`s sweep): @nf-addons/am-global-header@9.9.10 (GHSA-hj7v-p563-fffq) and @osl-design/react@9.9.10 (GHSA-qx4v-776h-xcpw) - both published 2026-09-24 late in the day, both matching the exact algamil7x day-7 primitive catalogued in yesterdays [multi-2026-09-24 sweep](/incident/multi-2026-09-24-ghsa-malware-sweep) Cluster A: os.userInfo().username+os.hostname()+process.cwd() concatenated into a DNS label with a package-specific prefix (osldr for @osl-design/react), destination oob.algamil7x.xyz reconstructed at runtime from a hex/char-code array, modules loaded via module.constructor._load to defeat static analysis of require() strings, execution triggered both at install (scripts.install) and on require() inside a swallowed try/catch. The @nf-addons and @osl-design scopes are two more scoped-lookalike targets in the operators scope-per-day cadence and had not been previously seen from this operator. This confirms nine consecutive days from a single operator (day-1 2026-09-18 @tink/tink-link-core -> day-7 2026-09-24) using the same DNS zone. No fresh algamil7x-branded advisories have appeared in the 2026-09-25 batch so far - either day-8 is skipped or the ecosystem trackers have not yet caught up
  • Cluster B - npm n8n-nodes-moonlet-helpers/-utils + n8n-nodes-flowstats mkicom.com dropper family (new operator): n8n-nodes-moonlet-helpers@1.0.0/1.0.4 (GHSA-hh4f-fhfw-7vgw) and n8n-nodes-moonlet-utils@1.0.0 (GHSA-f77h-w3rc-2c74) both ship an empty index.js (module.exports = {}) alongside a postinstall.js that fetches an unsigned binary from https://mkicom.com/.well-known/pki-validation/ct_pn8 (helpers) or .../ct_dn8 (utils), writes it to /tmp/.np or /tmp/.nc with chmod 0755, and executes it as a detached background process via a shell + setsid wrapper. The .well-known/pki-validation/ path is deliberately chosen to look like routine ACME/CT traffic to a network monitor. n8n-nodes-flowstats@1.0.0 (GHSA-wm7h-qmp4-782c) is the same operator with two additional primitives: on module load it checks n8n-specific env vars and, if seen, issues an HTTPS GET to the bare IP 104.21.3.16 with a Host: mkicom.com spoof header then executes the returned payload; separately its exported nodes execute() accepts {cmd, k} from HTTP request payloads and, when k === "kx9p26", passes cmd straight to child_process.exec (25-second timeout) - a magic-key backdoor in an n8n node that a self-hosted n8n user would expose to the internet by default. Persistence files: /tmp/.np, /tmp/.nc, /tmp/.fs_dev, /tmp/.fs_prod`. All three appear to target self-hosted n8n workflow-automation deployments
  • Cluster C - npm JPEG-hidden VBS/PowerShell Windows dotenv-typosquat dropper family: secure-env3@1.0.1 (GHSA-w2g5-xcc6-p474) and better-dotenv3@1.0.1 (GHSA-qx8m-mvxg-49m3). Both impersonate the dotenv env-loader library. Payload reads a bundled dist/stest.jpg, parses its JPEG APP13/APP14 marker segment (0xED/0xEE) to extract an encoded UTF-8 payload, writes it as a self-deleting .vbs wrapper to os.tmpdir(), and launches wscript.exe -> powershell.exe with encoded commands. better-dotenv3s internal package.json declares itself as node-env-buffer@2.2.6 (different published name), suggesting the same JPEG-loader stager is being redistributed under a rotating set of dotenv`-variant names. Executable names and PowerShell switches are assembled at runtime by joining split character arrays to evade static string scanners. Triggers on module import/require AND on CLI startup, not only on install. Windows-only
  • *Cluster D - npm `agency-test postinstall wscript.exe 4444.vbs AES+ChaCha20 Windows dropper family**: agency-test-exercise@1.0.2 (GHSA-qwj9-hfhg-j6vh) and agency-testts@1.0.0 (GHSA-75mh-8gwp-9cvf). Both declare postinstall: wscript.exe 4444.vbs in package.json. The bundled 4444.vbs is ~660-674 KB and holds a base64 string array that is reassembled and decrypted through layered AES-256-CBC + ChaCha20-IETF (embedded keys stateFKK, manifestGCP). Decrypted payload is written to %TEMP% as a random .dat file and passed to PowerShell for in-memory execution + process hollowing. Additional Windows-API-call name obfuscation via XOR-encoded strings. Package README fraudulently self-labels as a "Device Telemetry Aggregator". Amazon Inspector hash: 43eddaf152e2aa60b9f823513a2d9b11fc424a5cff4bb3c031f6823a48dc2f4e` (agency-test-exercise). Windows-only
  • Cluster E - npm chromatitle/chromatitle-js obfuscated fetch-and-execute (ANSI-color lure): chromatitle@1.0.0 (GHSA-7pgp-qm32-53rp) and chromatitle-js@1.0.0 (GHSA-93mr-5j8f-6p3w). The main entry unconditionally executes a ~51KB javascript-obfuscator payload (400-entry rotated string array, hex-escaped identifiers, RC4-style decoder, self-defending IIFE). The decoded code imports https.get, http.get, fs.createWriteStream, child_process.execFile/spawn, and platform-detects Windows/Linux/macOS/FreeBSD/SunOS before branching. Fires on module load (import/require) not on install script, so --ignore-scripts does NOT block it. Any downstream package that transitively imports either variant triggers the loader. Source hash for chromatitle: 793cf7eb2b4de9c41e229fc89c393e38f05141991762f69f310e1397fa464f9c. The two-name split (chromatitle + chromatitle-js) matches a pattern seen elsewhere in the corpus where one operator publishes the same payload under a bare name and a -js suffix to catch typos
  • Cluster F - npm wallet-connect-adapter@1.4.2 Windows XOR-encrypted Python dropper (GHSA-39rm-rv2w-366r): postinstall script runs a loader that decodes an embedded ~8KB blob, decrypts it via XOR with a hardcoded 32-byte key, silently installs the requests Python package via pip if missing, then executes the decrypted Python payload in a hidden detached child process. Package os field is restricted to ["win32"] so the malware only fires on Windows installers. The stub index.js exports nothing functional - a lure impersonating a WalletConnect adapter to catch npm-search hits. Windows-only. --ignore-scripts blocks this one
  • Cluster G - npm simple-date-formatter-new-11/13/14/15 - continuation of the 124.221.154.135 + oast.fun campaign tracked since 2026-08-03: simple-date-formatter-new-11@1.0.0 (GHSA-2v58-3f75-j4jv) queries cloud instance-metadata endpoints (Alibaba 100.100.100.200, AWS 169.254.169.254, Tencent) and exfils to pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun (Project Discovery Interactsh); on import it scans ~/.ssh and HTTPS-POSTs key filenames + username + platform to 124.221.154.135:443/post - same C2 IP as -new-9/-new-10 catalogued 2026-08-10. simple-date-formatter-new-13@1.0.0 (GHSA-539g-4gx9-g555) is a bsrc-SSRF variant: postinstall curls bsrc-ssrf.n.baidu-int.com/6395292252 (an internal Baidu SSRF target) and exfils the response to pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun/bsrc. simple-date-formatter-new-14@1.0.0 (GHSA-7r88-5m7v-8m5w) nslookups 9e954818.log.dnslogs.dpdns.org (dnslogs.dpdns.org OOB service) and separately HTTPS-POSTs SSH keys to 124.221.154.135. simple-date-formatter-new-15@1.0.0 (GHSA-fj2x-7537-68xm) is the same SSH-key + cloud-metadata payload as -new-11 with metadata.tencentyun.com and 169.254.0.23 added and a placeholder host YOUR_BURP_SERVER left in the code (PoC/typosquat stub). The 124.221.154.135 IP has been operator infrastructure since at least 2026-08-10 (previous port :4444, current port :443)
  • Cluster H - npm aliftech-ui/@birbalo/aliftech-ui shared-webhook.site dep-confusion siblings: aliftech-ui@99.9.9 (GHSA-648v-rwj3-6j2f) and @birbalo/aliftech-ui@99.9.9 (GHSA-383w-gxv7-cg2f). Both ship a postinstall.js that reads os.hostname() + os.userInfo().username and embeds those in the URL path of an HTTPS request to the exact same collector: https://webhook.site/539f8bb9-497a-4104-92f7-f95a77204cc2/. One operator running two lures - an unscoped aliftech-ui and a @birbalo/-scoped variant, both at sentinel dep-confusion version 99.9.9. Amazon Inspector attribution. Aliftech is a real fintech vendor with a legitimate internal aliftech-ui design system - almost certainly a targeted dep-confusion attempt against that org
  • Cluster I - npm @alphaspace/core Yahoo-internal dep-confusion + Pipedream exfil + istio/yahoo DNS recon: @alphaspace/core@99.0.0/99.0.1/99.0.2 (GHSA-5qqj-qfpp-jfqw). Preinstall script POSTs a JSON payload with hostname + username + Node version + package.json contents + npm registry config to https://f5778d1d81cc30c39dcdd0da5ca1d49a.m.pipedream.net, then issues DNS lookups against specific Yahoo internal hostnames including istio-system.prod1-gq1.omega.yahoo.com and buildr.corp.yahoo.com, then HTTPS-GETs those hosts with NODE_TLS_REJECT_UNAUTHORIZED=0 and captures the response bodies. Sentinel version 99.0.0+ is the dep-confusion attention-getter; the specific Yahoo internal hostnames + @alphaspace scope target the Yahoo/Verizon Media internal build stack. Amazon Inspector hash: 42d10ba1427af01794dfb0a6b39a05f969547455e9d86d75f18601b1d035c507. Whether this is a legitimate bug-bounty engagement or an attacker probing the same target, any lockfile hit at Yahoo/Apollo/Verizon Media should be treated as a real dep-confusion attempt against internal infra
  • Cluster J - npm eslint-config-compact-base@1.0.0 AWS API Gateway CI reconnaissance (GHSA-ghfm-6qx4-q8p4): on require(), exfils OS platform, hostname, username, arch, Node version, CWD, and the CI env vars CI / RUNNER_NAME / GITHUB_REPOSITORY as query-string params to https://cbrsuo9293.execute-api.us-east-1.amazonaws.com/c (attacker-controlled API Gateway). Fires on module load, so lint runs inside CI trigger it. Hash dbc01e3a8316b2d4e11b34a9c8cbe1cf5bd2af83a6a70052e40a22b54f13f78b. Recon-only - platform+hostname+repo name, no secret material exfiltrated - but pairs the org name (GITHUB_REPOSITORY) with the CI runner identity, which is enough to target follow-on attacks against that repo
  • Cluster K - npm c2-client@1.0.0 postinstall command channel (GHSA-h7qv-4h6m-4g2x): postinstall: node setup.js runs attacker-controlled code at install time under installer privileges. Advisory body is CWE-506 boilerplate without published IOC/payload analysis - treat as a probe or a lure whose payload was not captured. The name c2-client is unusually candid; likely a red-team artefact left published
  • Cluster L - pip prosocks proxy-network hijack campaign + my-private-pkg + vercel-runtime-python Vercel dep-confusion pentests: pip prosocks@1.0.0-1.0.9/1.0.13-1.0.23/1.0.25-1.0.32 (GHSA-6v7p-c53r-646f) contains embedded code that auto-joins the installer machine to a proxy network - a residential-proxy hijack that turns any developer or CI runner that ran pip install prosocks into an unwitting proxy exit node. Persistence + auto-run classification. Wide version range across ~30 published versions is unusual for a probe and consistent with an operator publishing successive builds of a working payload. pip my-private-pkg@99.1.1 (GHSA-v7x9-wx5x-qrpp) is a Vercel dep-confusion lure whose install command collects os.getlogin(), socket.gethostname(), local IP, os.getcwd(), platform.system()/machine() and POSTs to webhook.site/d4d1b01b-708a-40b9-b8c8-187eeecafeed; the package also ships a vercel_runtime_python module name to mimic Vercels Python runtime. pip vercel-runtime-python@0.1.0/99.99.99/100.99.99/100.100.99 (GHSA-fvc2-927p-99h8) is the sibling Vercel-runtime-Python dep-confusion probe: setup.py install override + import-time host exfil, classified PROBABLY_PENTEST. Both my-private-pkg and vercel-runtime-python` target Vercel internal builds

What to do

  1. 1Grep every package-lock.json, yarn.lock, pnpm-lock.yaml, package.json, requirements.txt, Pipfile.lock, poetry.lock in your org for every package name in Clusters A through L. Uninstall on hit, wipe node_modules/.venv, delete the lockfile, rebuild against a clean cache. Clusters A, B, C, D, E, F, G, H, I, J, and L all include confirmed real payloads (DNS-OOB exfil, mkicom.com binary dropper + magic-key RCE, JPEG-hidden Windows PowerShell dropper, Windows AES/ChaCha20 dropper, obfuscated fetch-and-execute, XOR Python dropper, SSH-key exfil to 124.221.154.135, webhook.site recon, Yahoo-targeted dep-confusion, CI recon, proxy-network hijack) - a hit on any of those is a compromise, not a warning
  2. 2For Cluster A (@nf-addons/am-global-header + @osl-design/react algamil7x day-7 late-adds): keep the oob.algamil7x.xyz resolver block in place from prior days (this is now day 7 confirmed with two late additions). The .xyz zone block is the durable mitigation because the operator picks a fresh internal-lookalike scope every 24 hours. If your org owns an @nf-addons or @osl-design scope internally, pin the legitimate scope in .npmrc to your private registry so the public malware cannot resolve preferentially. Rotate any credential accessible from a host that install-ran either package
  3. 3*For Cluster B (`n8n-nodes- mkicom.com dropper family)**: uninstall on hit. Any self-hosted n8n runner that ran npm install n8n-nodes-moonlet-helpers, n8n-nodes-moonlet-utils, or n8n-nodes-flowstats in the last 48h has an attacker-controlled binary running as a detached background process - kill any process holding /tmp/.np, /tmp/.nc, /tmp/.fs_dev, or /tmp/.fs_prod, image the host if it faced the internet. For n8n-nodes-flowstats specifically, if the compromised node was ever mounted into an active n8n workflow with an HTTP-triggered endpoint, treat that workflows HTTP endpoint as an exposed child_process.exec gateway keyed on k=kx9p26. Block mkicom.com at your resolver AND at your web proxy; the .well-known/pki-validation/ path was chosen to blend with ACME traffic so a path-based block is required. Block 104.21.3.16 at network egress
  4. 4For Cluster C (secure-env3 + better-dotenv3 JPEG-hidden dotenv dropper): uninstall on hit. On any Windows host that install-ran or import-ran either package, treat the box as compromised - the payload writes a self-deleting .vbs to %TEMP% and hands off to PowerShell so the disk artefact is gone by the time you look. Look at PowerShell script-block logging (Event ID 4104) and AMSI logs around the install time for encoded-command executions. Rotate any credential accessible to the local user account. Because the package.json is renamed internally (better-dotenv3 publishes as node-env-buffer@2.2.6), pin your dotenv dependency to the specific real dotenv package by exact name in your lockfile and reject any resolution to secure-env*, better-dotenv*, or node-env-buffer variants
  5. 5For Cluster D (agency-test-exercise + agency-testts Windows AES/ChaCha20 dropper): uninstall on hit. Any Windows host that ran npm install on either package has run a random .dat file from %TEMP% through PowerShell + process hollowing - image the host, dont attempt in-place cleanup. Look for a random-named .dat file created in %TEMP%` around the install time and preserve it for analysis before wiping
  6. 6For Cluster E (chromatitle + chromatitle-js obfuscated fetch-and-execute): uninstall on hit. --ignore-scripts does NOT block this family - the fetch-and-execute chain fires when the module is required, not when it is installed. Any downstream package that transitively depends on either variant will trigger the payload at build time or import time. Grep your dep tree with npm ls chromatitle chromatitle-js and yank both from any lockfile they appear in. Block outbound HTTPS to any endpoint that shows up when you decode the string array - the runtime target is not visible in the static source
  7. 7For Cluster F (wallet-connect-adapter Windows Python dropper): uninstall on hit. Windows-only, install-script-triggered, so --ignore-scripts blocks new installs. Look for a Python requests install with no matching legitimate requirements.txt on any Windows host in the last 48h - it is the giveaway that this loader ran. Rotate any credential accessible to the installer user account and check for a hidden detached Python process
  8. 8For Cluster G (simple-date-formatter-new-11/13/14/15 SSH-key + oast.fun continuation): block outbound to 124.221.154.135 (both :443 and :4444 from prior versions), pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun, and 9e954818.log.dnslogs.dpdns.org at CI network egress. On any hit, rotate every SSH key in ~/.ssh on the affected host - the attacker has the file listing at minimum and, for -new-11/-14/-15, the key filenames + username + platform. For -new-13 specifically, if you run internal Baidu network infrastructure, review whether bsrc-ssrf.n.baidu-int.com/6395292252 returned anything sensitive to the compromised host during the install window. The -new-<NNN> naming pattern is now a confirmed cross-month campaign; add a lockfile-lint rule that rejects any simple-date-formatter-new-* name outright
  9. 9For Cluster H (aliftech-ui + @birbalo/aliftech-ui webhook.site dep-confusion): uninstall on hit. If your org uses the legitimate Aliftech aliftech-ui design system internally, pin it in .npmrc to your private registry so the public sentinel 99.9.9 cannot resolve preferentially. Rotate no secrets (hostname + username only) but treat the presence of either package in a lockfile as evidence that the operator has probed for your internal-package name and expect follow-on attempts under a related name
  10. 10For Cluster I (@alphaspace/core Yahoo-internal dep-confusion): uninstall on hit. If you work on Yahoo/Apollo/Verizon Media internal infrastructure and the @alphaspace/core name appears in any lockfile, treat it as a real dep-confusion attempt against your build stack; contact security@yahoo. The NODE_TLS_REJECT_UNAUTHORIZED=0 side-effect persists for the lifetime of any long-running Node process the package touched. Block f5778d1d81cc30c39dcdd0da5ca1d49a.m.pipedream.net at your network egress. Even if this is a legitimate bug-bounty engagement against Yahoo, the payload will still ship system metadata to the researcher`s Pipedream endpoint on every install
  11. 11For Cluster J (eslint-config-compact-base AWS API Gateway CI recon): uninstall on hit. Recon-only (os.platform/os.hostname/os.userInfo/process.env.GITHUB_REPOSITORY only, no secret material), but the operator now has your CI runner name paired with your public repo name and can target follow-on attempts. Block cbrsuo9293.execute-api.us-east-1.amazonaws.com at CI network egress. Do NOT commit the removal in the same PR as any other change - a subsequent commit reverting the removal would silently re-establish exfil
  12. 12For Cluster K (c2-client postinstall command channel): uninstall on hit. Payload is undocumented - treat as install-time compromise until you can inspect the tarball. Rotate any credential accessible from the install account
  13. 13For Cluster L (pip prosocks proxy-hijack + my-private-pkg + vercel-runtime-python Vercel dep-confusion): for prosocks, any dev workstation or CI runner that ran pip install prosocks==<any version 1.0.0-1.0.32> in the last two weeks is now an operator-controlled proxy exit node - image the host and rotate every credential visible to the installer user; your outbound residential/CI IP is now attributable to third-party traffic sent through the proxy, which is a legal + reputation exposure distinct from the credential-theft risk. For my-private-pkg and vercel-runtime-python, block webhook.site/d4d1b01b-708a-40b9-b8c8-187eeecafeed at your network egress; if you run Vercel internal infrastructure, pin the real vercel_runtime_python to your private registry
  14. 14For every npm install in CI, prefer --ignore-scripts and enforce it at the runner level (note it does NOT block Clusters C or E - both fire at require/module-load, not on install script). Layer with egress denylists on oob.algamil7x.xyz, mkicom.com (including the fake .well-known/pki-validation/ path), 104.21.3.16, 124.221.154.135, pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun, 9e954818.log.dnslogs.dpdns.org, webhook.site (or specifically the two campaign paths listed above), f5778d1d81cc30c39dcdd0da5ca1d49a.m.pipedream.net, and cbrsuo9293.execute-api.us-east-1.amazonaws.com. Extend the pin-lists from prior sweeps with @nf-addons/am-global-header, @osl-design/react, n8n-nodes-moonlet-helpers, n8n-nodes-moonlet-utils, n8n-nodes-flowstats, secure-env3, better-dotenv3, agency-test-exercise, agency-testts, chromatitle, chromatitle-js, wallet-connect-adapter, simple-date-formatter-new-11, simple-date-formatter-new-13, simple-date-formatter-new-14, simple-date-formatter-new-15, aliftech-ui, @birbalo/aliftech-ui, @alphaspace/core, eslint-config-compact-base, c2-client, pip prosocks, pip my-private-pkg, pip vercel-runtime-python

References

multi-2026-09-25-ghsa-malware-sweep