# GitHub Advisory malware sweep - 2026-09-24 (late) + 2026-09-25 (npm `@nf-addons/am-global-header` + `@osl-design/react` `oob.algamil7x.xyz` DNS-OOB day-7 late-adds missed by yesterday`s sweep; `n8n-nodes-moonlet-helpers`/`-utils`/`n8n-nodes-flowstats` `mkicom.com` fake `.well-known/pki-validation/` dropper family with `104.21.3.16` bare-IP + magic-key RCE; `secure-env3` + `better-dotenv3` JPEG-APP13/APP14 hidden VBS/PowerShell Windows dotenv typosquat dropper family; `agency-test-exercise` + `agency-testts` `wscript.exe 4444.vbs` AES+ChaCha20 Windows dropper; `chromatitle` + `chromatitle-js` ANSI-color-lure obfuscated fetch-and-execute; `wallet-connect-adapter` Windows XOR-encrypted Python dropper; `simple-date-formatter-new-11/13/14/15` continuation of the `124.221.154.135` SSH-key + `oast.fun` campaign (13/14/15 new C2 hosts); `aliftech-ui` + `@birbalo/aliftech-ui` shared-`webhook.site` dep-confusion siblings; `@alphaspace/core` Yahoo-internal dep-confusion Pipedream + istio/yahoo DNS recon; `eslint-config-compact-base` AWS API Gateway CI recon; `c2-client` postinstall command channel; pip `prosocks` proxy-network hijack campaign + `my-private-pkg` + `vercel-runtime-python` Vercel dep-confusion pentests)

> GHSA 2026-09-24 (late) + 2026-09-25: ~24 new npm advisories + 3 pip. Two `oob.algamil7x.xyz` day-7 late-adds yesterday`s sweep missed (`@nf-addons/am-global-header`, `@osl-design/react`). New `n8n-nodes-*` `mkicom.com` dropper family. `secure-env3`/`better-dotenv3` JPEG-hidden Windows dropper family. `simple-date-formatter-new-11/13/14/15` extend the `124.221.154.135` campaign. `@alphaspace/core` targets Yahoo internal builds.

- Published: 2026-09-25
- Severity: high
- Kind: Advisory sweep - A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
- Ecosystems: npm, PyPI
- Scope: 24 packages, 58 compromised versions
- Tags: dependency-confusion, typosquat, dns-exfiltration, credential-theft, obfuscation, ci-cd-compromise, infostealer
- Also known as: 2026-09-25 GHSA npm sweep, @nf-addons + @osl-design algamil7x.xyz day-7 late-adds, n8n-nodes-* mkicom.com dropper family, secure-env3 + better-dotenv3 JPEG-hidden dotenv dropper family, agency-test-exercise + agency-testts 4444.vbs AES dropper, chromatitle + chromatitle-js obfuscated fetch-and-execute, wallet-connect-adapter Windows Python dropper, simple-date-formatter-new-11/13/14/15 124.221.154.135 continuation, @alphaspace/core Yahoo internal dep-confusion, prosocks proxy-network hijack (2026-09-prosocks), my-private-pkg + vercel-runtime-python Vercel dep-confusion
- Detected by: GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector, Safedep, kam193/bad-packages, jaschadub/compromised-packages-check
- Incident ID: multi-2026-09-25-ghsa-malware-sweep

## Affected packages (24)

Only the exact versions listed were named by the source advisories. Other versions are not implicated.

| Package | Ecosystem | Compromised versions |
|---|---|---|
| [@alphaspace/core](https://dependencywatch.io/package/npm/@alphaspace/core) | npm | 99.0.0, 99.0.1, 99.0.2 |
| [@birbalo/aliftech-ui](https://dependencywatch.io/package/npm/@birbalo/aliftech-ui) | npm | 99.9.9 |
| [@nf-addons/am-global-header](https://dependencywatch.io/package/npm/@nf-addons/am-global-header) | npm | 9.9.10 |
| [@osl-design/react](https://dependencywatch.io/package/npm/@osl-design/react) | npm | 9.9.10 |
| [agency-test-exercise](https://dependencywatch.io/package/npm/agency-test-exercise) | npm | 1.0.2 |
| [agency-testts](https://dependencywatch.io/package/npm/agency-testts) | npm | 1.0.0 |
| [aliftech-ui](https://dependencywatch.io/package/npm/aliftech-ui) | npm | 99.9.9 |
| [better-dotenv3](https://dependencywatch.io/package/npm/better-dotenv3) | npm | 1.0.1 |
| [c2-client](https://dependencywatch.io/package/npm/c2-client) | npm | 1.0.0 |
| [chromatitle](https://dependencywatch.io/package/npm/chromatitle) | npm | 1.0.0 |
| [chromatitle-js](https://dependencywatch.io/package/npm/chromatitle-js) | npm | 1.0.0 |
| [eslint-config-compact-base](https://dependencywatch.io/package/npm/eslint-config-compact-base) | npm | 1.0.0 |
| [my-private-pkg](https://dependencywatch.io/package/pypi/my-private-pkg) | PyPI | 99.1.1 |
| [n8n-nodes-flowstats](https://dependencywatch.io/package/npm/n8n-nodes-flowstats) | npm | 1.0.0 |
| [n8n-nodes-moonlet-helpers](https://dependencywatch.io/package/npm/n8n-nodes-moonlet-helpers) | npm | 1.0.0, 1.0.4 |
| [n8n-nodes-moonlet-utils](https://dependencywatch.io/package/npm/n8n-nodes-moonlet-utils) | npm | 1.0.0 |
| [prosocks](https://dependencywatch.io/package/pypi/prosocks) | PyPI | 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.13, 1.0.14, 1.0.15, 1.0.16, 1.0.17, 1.0.18, 1.0.19, 1.0.20, 1.0.21, 1.0.22, 1.0.23, 1.0.25, 1.0.26, 1.0.27, 1.0.28, 1.0.29, 1.0.30, 1.0.31, 1.0.32 |
| [secure-env3](https://dependencywatch.io/package/npm/secure-env3) | npm | 1.0.1 |
| [simple-date-formatter-new-11](https://dependencywatch.io/package/npm/simple-date-formatter-new-11) | npm | 1.0.0 |
| [simple-date-formatter-new-13](https://dependencywatch.io/package/npm/simple-date-formatter-new-13) | npm | 1.0.0 |
| [simple-date-formatter-new-14](https://dependencywatch.io/package/npm/simple-date-formatter-new-14) | npm | 1.0.0 |
| [simple-date-formatter-new-15](https://dependencywatch.io/package/npm/simple-date-formatter-new-15) | npm | 1.0.0 |
| [vercel-runtime-python](https://dependencywatch.io/package/pypi/vercel-runtime-python) | PyPI | 0.1.0, 99.99.99, 100.99.99, 100.100.99 |
| [wallet-connect-adapter](https://dependencywatch.io/package/npm/wallet-connect-adapter) | npm | 1.4.2 |

## What happened

Between roughly 2026-09-24 12:00 UTC and 2026-09-25 12:00 UTC, GitHub Advisory Database (plus the OpenSSF malicious-packages bulk export, Amazon Inspector`s IN-MAL feed, and Safedep`s compromised-package tracker) published approximately 24 new npm malware advisories and 3 new pip advisories. The window is dominated by two `oob.algamil7x.xyz` day-7 late-adds that yesterday`s sweep missed, a new `mkicom.com` `n8n-nodes-*` dropper family, a Windows JPEG-hidden VBS/PowerShell `dotenv`-typosquat family, a `simple-date-formatter-new-*` continuation of the `124.221.154.135` SSH-key campaign, and one Yahoo-internal dep-confusion attempt (`@alphaspace/core`).

## Cluster A - `@nf-addons/am-global-header` + `@osl-design/react` `oob.algamil7x.xyz` day-7 late-adds (MISSED by yesterday`s sweep)

| Package | Version | GHSA | Prefix in DNS label |
|---|---|---|---|
| `@nf-addons/am-global-header` | `9.9.10` | GHSA-hj7v-p563-fffq | (not published) |
| `@osl-design/react` | `9.9.10` | GHSA-qx4v-776h-xcpw | `osldr` |

Both match the exact algamil7x day-7 primitive:

- `os.userInfo().username` + `os.hostname()` + `process.cwd()` concatenated into a DNS label
- Destination `oob.algamil7x.xyz` stored as a hex/char-code array in a `lib/*.js` module
- Destination reconstructed at runtime via `String.fromCharCode`
- `os`, `dns` modules loaded via `module.constructor._load` rather than literal `require()` to defeat static analysis
- Fires both at install (`scripts.install`) and on `require()`, wrapped in a swallowed try/catch

**This confirms the operator on day 7 (2026-09-24)** using two more scoped-lookalike names, extending the campaign from the [multi-2026-09-24 sweep](https://dependencywatch.io/incident/multi-2026-09-24-ghsa-malware-sweep) Cluster A (which caught `@baanx/common`, `@baanx/domain`, `@insiderintelligence/componentlibrary` but not these two).

Day-1 through day-7 recap:
- Day 1 (2026-09-18): `@tink/tink-link-core`
- Day 2 (2026-09-19): `@insiderintelligence/googleadmanager`
- Day 3 (2026-09-20): `@insiderintelligence/*` variants
- Day 4 (2026-09-21): `@baanx/solana-lib` etc
- Day 5 (2026-09-22): `@baanx/abis`, `@baanx/blockchain-config`
- Day 6 (2026-09-23): `@tvg-mar/*`, `@user-services/*`
- Day 7 (2026-09-24): `@baanx/common`, `@baanx/domain`, `@insiderintelligence/componentlibrary`, `@nf-addons/am-global-header`, `@osl-design/react`

**No fresh algamil7x-branded advisories have appeared in the 2026-09-25 batch as of publication.** Either the operator paused, day-8 has not yet propagated to the trackers, or day-7`s late additions were the tail of the campaign.

## Cluster B - npm `n8n-nodes-moonlet-helpers`/`-utils` + `n8n-nodes-flowstats` `mkicom.com` dropper family (new operator)

| Package | Version | GHSA | Trigger | Payload path |
|---|---|---|---|---|
| `n8n-nodes-moonlet-helpers` | `1.0.0`/`1.0.4` | GHSA-hh4f-fhfw-7vgw | postinstall | `mkicom.com/.well-known/pki-validation/ct_pn8` -> `/tmp/.np` |
| `n8n-nodes-moonlet-utils` | `1.0.0` | GHSA-f77h-w3rc-2c74 | postinstall | `mkicom.com/.well-known/pki-validation/ct_dn8` -> `/tmp/.nc` |
| `n8n-nodes-flowstats` | `1.0.0` | GHSA-wm7h-qmp4-782c | module load + node execute | `104.21.3.16` (Host: `mkicom.com`); magic-key RCE via `{cmd, k:"kx9p26"}` |

All three ship an empty stub `index.js` (`module.exports = {}` or trivial), doing no legitimate work. The `postinstall.js` (moonlet-helpers/utils) or module-load hook (flowstats) fetches an opaque binary via HTTPS from `mkicom.com` (or the bare IP `104.21.3.16` with a spoofed Host header for flowstats), writes it under `/tmp/.<letters>` with `chmod 0755`, and executes it detached via a shell + `setsid` wrapper. Zero hash verification, zero signature, zero version pinning.

The path `.well-known/pki-validation/` is chosen to blend with legitimate ACME certificate-transparency traffic - a host-based block is easily bypassed by moving to a new host under the same path convention, so a path-based block is needed too.

**`n8n-nodes-flowstats` adds two additional primitives** on top of the shared dropper:

1. **Module-load beacon**: on `require()` the code checks n8n-specific env vars; if any are set, it issues an HTTPS GET to `104.21.3.16` with `Host: mkicom.com` and executes the returned payload via shell
2. **Magic-key backdoor**: the exported n8n node`s `execute()` accepts `{cmd, k}` from HTTP request payloads; when `k === "kx9p26"`, `cmd` is passed to `child_process.exec` with a 25-second timeout

This is a *fully-usable backdoor* aimed at self-hosted n8n workflow-automation deployments - anyone who imported the flowstats node into a webhook-triggered n8n workflow has exposed a `child_process.exec` gateway to the internet.

## Cluster C - JPEG-hidden VBS/PowerShell Windows dotenv-typosquat dropper family

| Package | Version | GHSA | JPEG segment | Notes |
|---|---|---|---|---|
| `secure-env3` | `1.0.1` | GHSA-w2g5-xcc6-p474 | APP14 (`0xEE`) | Self-deleting VBS -> wscript.exe -> powershell.exe |
| `better-dotenv3` | `1.0.1` | GHSA-qx8m-mvxg-49m3 | APP13 (`0xED`) | Internal `package.json` name is `node-env-buffer@2.2.6` |

Both impersonate the `dotenv` library. The bundled `dist/stest.jpg` is a real JPEG with a hidden payload embedded in one of its non-standard APPn marker segments. On module import/require or CLI startup (Windows only), the code:

1. Reads `dist/stest.jpg`
2. Parses the APP13 or APP14 segment to extract the encoded UTF-8 payload
3. Writes a self-deleting `.vbs` wrapper to `os.tmpdir()`
4. Launches `wscript.exe <path>.vbs`, which chains to `powershell.exe` with encoded commands

Executable names and PowerShell switches are assembled at runtime by joining split character arrays to evade static string scanners. The fact that `better-dotenv3`'s internal `package.json` declares a different name (`node-env-buffer@2.2.6`) suggests the same JPEG-loader stager is being redistributed under a rotating set of `dotenv`-variant published names - expect more `*-dotenv*` and `*-env*` names to appear.

## Cluster D - `agency-test-exercise` + `agency-testts` `wscript.exe 4444.vbs` AES+ChaCha20 Windows dropper

`agency-test-exercise@1.0.2` (GHSA-qwj9-hfhg-j6vh) and `agency-testts@1.0.0` (GHSA-75mh-8gwp-9cvf). Both declare `postinstall: wscript.exe 4444.vbs` in `package.json`. The bundled `4444.vbs` is ~660-674KB and holds a base64 string array (~660 entries) that is reassembled and decrypted through layered AES-256-CBC + ChaCha20-IETF with embedded keys (`stateFKK`, `manifestGCP`). The decrypted payload lands in `%TEMP%` as a random `.dat` file and is passed to PowerShell for in-memory execution + process hollowing. Additional Windows-API-call-name obfuscation via XOR-encoded strings.

The fraudulent README self-labels as a "Device Telemetry Aggregator". Amazon Inspector hash: `43eddaf152e2aa60b9f823513a2d9b11fc424a5cff4bb3c031f6823a48dc2f4e` (agency-test-exercise).

## Cluster E - `chromatitle` + `chromatitle-js` obfuscated fetch-and-execute

`chromatitle@1.0.0` (GHSA-7pgp-qm32-53rp) and `chromatitle-js@1.0.0` (GHSA-93mr-5j8f-6p3w). Advertised as ANSI-color/title formatters. The main entry unconditionally executes a ~51KB javascript-obfuscator payload:

- 400-entry rotated string array
- Hex-escaped identifiers
- RC4-style decoder
- Self-defending IIFE that trips on tampering

The decoded code imports `https.get`, `http.get`, `fs.createWriteStream`, `child_process.execFile`/`spawn`, then platform-detects Windows/Linux/macOS/FreeBSD/SunOS and branches. `--ignore-scripts` does NOT block this - the fetch-and-execute fires when the module is required, not when it is installed.

Source hash for `chromatitle`: `793cf7eb2b4de9c41e229fc89c393e38f05141991762f69f310e1397fa464f9c`.

## Cluster F - `wallet-connect-adapter@1.4.2` Windows XOR-encrypted Python dropper

(GHSA-39rm-rv2w-366r). `postinstall` script runs a loader that decodes an embedded ~8KB blob, XOR-decrypts with a hardcoded 32-byte key, silently `pip install requests` if missing, then executes the decrypted Python payload as a hidden detached child process. Package `os` field is restricted to `["win32"]` so the malware only fires on Windows installers. The stub `index.js` is non-functional cover.

## Cluster G - `simple-date-formatter-new-11/13/14/15` (continuation of the `124.221.154.135` + `oast.fun` campaign since 2026-08-03)

| Package | Version | GHSA | C2 |
|---|---|---|---|
| `simple-date-formatter-new-11` | `1.0.0` | GHSA-2v58-3f75-j4jv | `124.221.154.135:443/post` + `pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun` |
| `simple-date-formatter-new-13` | `1.0.0` | GHSA-539g-4gx9-g555 | Baidu SSRF `bsrc-ssrf.n.baidu-int.com/6395292252` -> `pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun/bsrc` |
| `simple-date-formatter-new-14` | `1.0.0` | GHSA-7r88-5m7v-8m5w | `9e954818.log.dnslogs.dpdns.org` + `124.221.154.135` |
| `simple-date-formatter-new-15` | `1.0.0` | GHSA-fj2x-7537-68xm | `124.221.154.135:443/post` (placeholder `YOUR_BURP_SERVER` for cloud-metadata data) |

All four masquerade as three-line date-formatting stubs. The postinstall or on-import code enumerates cloud-provider instance-metadata endpoints (Alibaba `100.100.100.200`/`metadata.tencentyun.com`, AWS `169.254.169.254`, Tencent `169.254.0.23`), reads SSH keys from `~/.ssh`, and exfiltrates via HTTPS POST to `124.221.154.135:443/post` (same C2 IP as `-new-9`/`-new-10` catalogued 2026-08-10 on port `:4444` - port has moved, IP has not).

The `-new-13` variant swaps in a **Baidu internal SSRF target** at `bsrc-ssrf.n.baidu-int.com/6395292252`, which is a Baidu BSRC bug-bounty SSRF probe target - **so this specific package is almost certainly a Baidu-scoped bug-bounty probe not a broad attack** - but the other three (`-new-11`, `-new-14`, `-new-15`) carry the same SSH-key exfil primitive as `-new-9`/`-new-10` and should be treated as generalised credential theft.

**Campaign scope**: the `simple-date-formatter-new-<N>` naming pattern is now confirmed across `-new-1` (2026-08-03), `-new-9`/`-new-10` (2026-08-10), and `-new-11`/`-13`/`-14`/`-15` today. An operator publishing sequentially-numbered variants of the same lure name is worth catching with a lockfile-lint regex.

## Cluster H - `aliftech-ui` + `@birbalo/aliftech-ui` shared-webhook.site dep-confusion siblings

`aliftech-ui@99.9.9` (GHSA-648v-rwj3-6j2f) and `@birbalo/aliftech-ui@99.9.9` (GHSA-383w-gxv7-cg2f). Both ship a `postinstall.js` that reads `os.hostname()` + `os.userInfo().username` and encodes them in the URL path of an HTTPS request to `https://webhook.site/539f8bb9-497a-4104-92f7-f95a77204cc2/`. **Both packages share the exact same webhook UUID** - one operator running two lures.

Aliftech is a real fintech vendor with a legitimate internal `aliftech-ui` design system. The unscoped `aliftech-ui@99.9.9` on the public registry is the classic dep-confusion attention-getter; the `@birbalo/`-scoped variant is a fallback in case the internal build uses a scope. Amazon Inspector attribution.

## Cluster I - `@alphaspace/core` Yahoo-internal dep-confusion

`@alphaspace/core@99.0.0`/`99.0.1`/`99.0.2` (GHSA-5qqj-qfpp-jfqw). Preinstall script:

1. POSTs a JSON payload (hostname, username, Node version, `package.json` contents, npm registry config) to `https://f5778d1d81cc30c39dcdd0da5ca1d49a.m.pipedream.net`
2. DNS-looks up **specific Yahoo internal hostnames**: `istio-system.prod1-gq1.omega.yahoo.com`, `buildr.corp.yahoo.com`, and others
3. HTTPS-GETs those hosts with `NODE_TLS_REJECT_UNAUTHORIZED=0` and captures response bodies to the same collector

Amazon Inspector hash: `42d10ba1427af01794dfb0a6b39a05f969547455e9d86d75f18601b1d035c507`.

The specific Yahoo hostnames + `@alphaspace` scope target the Yahoo/Verizon Media internal build stack. This may be a legitimate bug-bounty engagement (Yahoo runs one) or an attacker probing the same target; either way any lockfile hit is evidence of a real dep-confusion attempt against the Yahoo internal build system.

## Cluster J - `eslint-config-compact-base` AWS API Gateway CI recon

`eslint-config-compact-base@1.0.0` (GHSA-ghfm-6qx4-q8p4). On `require()`, exfils OS platform, hostname, username, arch, Node version, CWD, and the CI env vars `CI` / `RUNNER_NAME` / `GITHUB_REPOSITORY` as query-string params to `https://cbrsuo9293.execute-api.us-east-1.amazonaws.com/c` (attacker-controlled API Gateway).

Hash `dbc01e3a8316b2d4e11b34a9c8cbe1cf5bd2af83a6a70052e40a22b54f13f78b`. Fires on module load, so any ESLint run in CI triggers it.

## Cluster K - `c2-client@1.0.0` postinstall command channel

(GHSA-h7qv-4h6m-4g2x). `postinstall: node setup.js` runs attacker-controlled code at install time under installer privileges. Advisory body is CWE-506 boilerplate without published IOC or payload analysis. Treat as install-time compromise pending analysis; the unusually candid name `c2-client` suggests a red-team artefact left published.

## Cluster L - pip: `prosocks` proxy-network hijack + `my-private-pkg` + `vercel-runtime-python` Vercel dep-confusion

| Package | Version | GHSA | Campaign |
|---|---|---|---|
| `prosocks` | `1.0.0`-`1.0.9`, `1.0.13`-`1.0.23`, `1.0.25`-`1.0.32` | GHSA-6v7p-c53r-646f | `2026-09-prosocks` proxy-network hijack |
| `my-private-pkg` | `99.1.1` | GHSA-v7x9-wx5x-qrpp | `vercel_runtime_python` dep-confusion / webhook.site |
| `vercel-runtime-python` | `0.1.0`, `99.99.99`, `100.99.99`, `100.100.99` | GHSA-fvc2-927p-99h8 | Vercel dep-confusion (PROBABLY_PENTEST) |

**`prosocks`** contains embedded code that auto-joins the installer machine to a proxy network - a residential-proxy hijack that turns any developer or CI runner into an unwitting proxy exit node. Persistence + auto-run classification. The ~30-version range is unusual for a probe and consistent with an operator publishing successive builds of a working payload.

**`my-private-pkg@99.1.1`** is a Vercel dep-confusion lure with an install command that collects `os.getlogin()`, `socket.gethostname()`, local IP, `os.getcwd()`, `platform.system()`/`machine()` and POSTs to `webhook.site/d4d1b01b-708a-40b9-b8c8-187eeecafeed`. The package additionally ships a `vercel_runtime_python` module to mimic Vercel`s Python runtime.

**`vercel-runtime-python@0.1.0/99.99.99/100.99.99/100.100.99`** is the sibling Vercel-runtime-Python dep-confusion probe: `setup.py` install override + import-time host exfil. Classification `PROBABLY_PENTEST`.

Both `my-private-pkg` and `vercel-runtime-python` target Vercel internal builds.

## Cross-operator patterns worth flagging

1. **The `oob.algamil7x.xyz` operator is now confirmed at nine consecutive days** with two late-Sept-24 adds (`@nf-addons/am-global-header`, `@osl-design/react`) that yesterday`s sweep missed. No day-8 (Sept 25) additions have appeared yet - the campaign may have paused. Still the longest-running single-operator campaign in the DependencyWatch 2026 Q3 corpus.
2. **Two independent Windows-postinstall PowerShell dropper families** land in the same 24-hour window: (i) the JPEG-hidden `.vbs` -> `wscript.exe` -> `powershell.exe` chain (`secure-env3`, `better-dotenv3` - Cluster C), and (ii) the pre-bundled `4444.vbs` AES+ChaCha20 chain (`agency-test-exercise`, `agency-testts` - Cluster D). Both target Windows exclusively; both use `wscript.exe` -> PowerShell handoff to defeat AMSI/EDR string-based detection. Expect more of this class as PowerShell-only detections harden.
3. **The `mkicom.com` operator** is new in the corpus - a fake `.well-known/pki-validation/` path suggests they know defenders look for anomalous outbound HTTP but not for outbound HTTPS to CT/PKI-shaped paths. The `n8n-nodes-flowstats` variant additionally ships a **usable HTTP magic-key backdoor** in what would become an internet-exposed n8n workflow node - a novel primitive not seen in other 2026 Q3 sweep entries.
4. **The `124.221.154.135` SSH-key + `.oast.fun` operator has now shipped seven public variants** under the `simple-date-formatter-new-*` naming pattern across two months (2026-08-03 `-new-1`, 2026-08-10 `-new-9`/`-new-10`, 2026-09-24 `-new-11`/`-13`/`-14`/`-15`), with C2 port moving `:4444` -> `:443` but the IP unchanged. The `-new-13` Baidu-SSRF variant is almost certainly a legitimate Baidu BSRC bug-bounty probe; the other six are broad credential theft.
5. **Yahoo-internal dep-confusion is back** (`@alphaspace/core`). Yahoo runs a bug-bounty program that accepts dep-confusion research so this may be legitimate research, but the payload still ships host + build metadata to a public Pipedream endpoint on every install.
6. **Vercel dep-confusion** appears in two coordinated pip packages this window (`my-private-pkg` and `vercel-runtime-python`) targeting Vercel`s Python runtime name.

## Registry state

All packages in Clusters A, C, D, E, F, G, H, I, J, K, L are npm/pip-quarantined (replaced with holding packages). Cluster B`s `n8n-nodes-*` packages have been yanked but the `mkicom.com` C2 infrastructure remains active. `124.221.154.135` (Cluster G), `f5778d1d81cc30c39dcdd0da5ca1d49a.m.pipedream.net` (Cluster I), `cbrsuo9293.execute-api.us-east-1.amazonaws.com` (Cluster J), `webhook.site/539f8bb9-...` (Cluster H) and `webhook.site/d4d1b01b-...` (Cluster L my-private-pkg) collectors all remain reachable at time of writing.

## Discovery credits

`GitHub Advisory Database`, `OpenSSF malicious-packages`, `OpenSSF Package Analysis`, `Amazon Inspector`, `Safedep`, `kam193/bad-packages`, `jaschadub/compromised-packages-check`. Per-package IOC details drawn from GHSA and OpenSSF advisory bodies published between 2026-09-24 12:00 UTC and 2026-09-25 12:00 UTC.

## Impact

- **Cluster A - npm `@nf-addons/am-global-header` + `@osl-design/react` `oob.algamil7x.xyz` DNS-OOB (day-7 late-adds MISSED by yesterday`s sweep)**: `@nf-addons/am-global-header@9.9.10` (GHSA-hj7v-p563-fffq) and `@osl-design/react@9.9.10` (GHSA-qx4v-776h-xcpw) - both published 2026-09-24 late in the day, both matching the exact algamil7x day-7 primitive catalogued in yesterday`s [multi-2026-09-24 sweep](https://dependencywatch.io/incident/multi-2026-09-24-ghsa-malware-sweep) Cluster A: `os.userInfo().username`+`os.hostname()`+`process.cwd()` concatenated into a DNS label with a package-specific prefix (`osldr` for `@osl-design/react`), destination `oob.algamil7x.xyz` reconstructed at runtime from a hex/char-code array, modules loaded via `module.constructor._load` to defeat static analysis of `require()` strings, execution triggered both at install (`scripts.install`) and on `require()` inside a swallowed try/catch. The `@nf-addons` and `@osl-design` scopes are two more scoped-lookalike targets in the operator`s scope-per-day cadence and had not been previously seen from this operator. **This confirms nine consecutive days from a single operator (day-1 2026-09-18 `@tink/tink-link-core` -> day-7 2026-09-24) using the same DNS zone.** No fresh algamil7x-branded advisories have appeared in the 2026-09-25 batch so far - either day-8 is skipped or the ecosystem trackers have not yet caught up
- **Cluster B - npm `n8n-nodes-moonlet-helpers`/`-utils` + `n8n-nodes-flowstats` `mkicom.com` dropper family (new operator)**: `n8n-nodes-moonlet-helpers@1.0.0`/`1.0.4` (GHSA-hh4f-fhfw-7vgw) and `n8n-nodes-moonlet-utils@1.0.0` (GHSA-f77h-w3rc-2c74) both ship an empty `index.js` (`module.exports = {}`) alongside a `postinstall.js` that fetches an unsigned binary from `https://mkicom.com/.well-known/pki-validation/ct_pn8` (helpers) or `.../ct_dn8` (utils), writes it to `/tmp/.np` or `/tmp/.nc` with `chmod 0755`, and executes it as a detached background process via a shell + `setsid` wrapper. The `.well-known/pki-validation/` path is deliberately chosen to look like routine ACME/CT traffic to a network monitor. `n8n-nodes-flowstats@1.0.0` (GHSA-wm7h-qmp4-782c) is the same operator with two additional primitives: on module load it checks n8n-specific env vars and, if seen, issues an HTTPS GET to the bare IP `104.21.3.16` with a `Host: mkicom.com` spoof header then executes the returned payload; separately its exported node`s `execute()` accepts `{cmd, k}` from HTTP request payloads and, when `k === "kx9p26"`, passes `cmd` straight to `child_process.exec` (25-second timeout) - a magic-key backdoor in an n8n node that a self-hosted n8n user would expose to the internet by default. Persistence files: `/tmp/.np`, `/tmp/.nc`, `/tmp/.fs_dev`, `/tmp/.fs_prod`. All three appear to target self-hosted n8n workflow-automation deployments
- **Cluster C - npm JPEG-hidden VBS/PowerShell Windows dotenv-typosquat dropper family**: `secure-env3@1.0.1` (GHSA-w2g5-xcc6-p474) and `better-dotenv3@1.0.1` (GHSA-qx8m-mvxg-49m3). Both impersonate the `dotenv` env-loader library. Payload reads a bundled `dist/stest.jpg`, parses its JPEG APP13/APP14 marker segment (`0xED`/`0xEE`) to extract an encoded UTF-8 payload, writes it as a self-deleting `.vbs` wrapper to `os.tmpdir()`, and launches `wscript.exe` -> `powershell.exe` with encoded commands. `better-dotenv3``s internal `package.json` declares itself as `node-env-buffer@2.2.6` (different published name), suggesting the same JPEG-loader stager is being redistributed under a rotating set of `dotenv`-variant names. Executable names and PowerShell switches are assembled at runtime by joining split character arrays to evade static string scanners. Triggers on module import/require AND on CLI startup, not only on install. Windows-only
- **Cluster D - npm `agency-test*` postinstall `wscript.exe 4444.vbs` AES+ChaCha20 Windows dropper family**: `agency-test-exercise@1.0.2` (GHSA-qwj9-hfhg-j6vh) and `agency-testts@1.0.0` (GHSA-75mh-8gwp-9cvf). Both declare `postinstall: wscript.exe 4444.vbs` in `package.json`. The bundled `4444.vbs` is ~660-674 KB and holds a base64 string array that is reassembled and decrypted through layered AES-256-CBC + ChaCha20-IETF (embedded keys `stateFKK`, `manifestGCP`). Decrypted payload is written to `%TEMP%` as a random `.dat` file and passed to PowerShell for in-memory execution + process hollowing. Additional Windows-API-call name obfuscation via XOR-encoded strings. Package README fraudulently self-labels as a "Device Telemetry Aggregator". Amazon Inspector hash: `43eddaf152e2aa60b9f823513a2d9b11fc424a5cff4bb3c031f6823a48dc2f4e` (agency-test-exercise). Windows-only
- **Cluster E - npm `chromatitle`/`chromatitle-js` obfuscated fetch-and-execute (ANSI-color lure)**: `chromatitle@1.0.0` (GHSA-7pgp-qm32-53rp) and `chromatitle-js@1.0.0` (GHSA-93mr-5j8f-6p3w). The main entry unconditionally executes a ~51KB javascript-obfuscator payload (400-entry rotated string array, hex-escaped identifiers, RC4-style decoder, self-defending IIFE). The decoded code imports `https.get`, `http.get`, `fs.createWriteStream`, `child_process.execFile`/`spawn`, and platform-detects Windows/Linux/macOS/FreeBSD/SunOS before branching. Fires on module load (import/require) not on install script, so `--ignore-scripts` does NOT block it. Any downstream package that transitively imports either variant triggers the loader. Source hash for `chromatitle`: `793cf7eb2b4de9c41e229fc89c393e38f05141991762f69f310e1397fa464f9c`. The two-name split (`chromatitle` + `chromatitle-js`) matches a pattern seen elsewhere in the corpus where one operator publishes the same payload under a bare name and a `-js` suffix to catch typos
- **Cluster F - npm `wallet-connect-adapter@1.4.2` Windows XOR-encrypted Python dropper (GHSA-39rm-rv2w-366r)**: `postinstall` script runs a loader that decodes an embedded ~8KB blob, decrypts it via XOR with a hardcoded 32-byte key, silently installs the `requests` Python package via pip if missing, then executes the decrypted Python payload in a hidden detached child process. Package `os` field is restricted to `["win32"]` so the malware only fires on Windows installers. The stub `index.js` exports nothing functional - a lure impersonating a WalletConnect adapter to catch npm-search hits. Windows-only. `--ignore-scripts` blocks this one
- **Cluster G - npm `simple-date-formatter-new-11/13/14/15` - continuation of the `124.221.154.135` + `oast.fun` campaign tracked since 2026-08-03**: `simple-date-formatter-new-11@1.0.0` (GHSA-2v58-3f75-j4jv) queries cloud instance-metadata endpoints (Alibaba `100.100.100.200`, AWS `169.254.169.254`, Tencent) and exfils to `pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun` (Project Discovery Interactsh); on import it scans `~/.ssh` and HTTPS-POSTs key filenames + username + platform to `124.221.154.135:443/post` - same C2 IP as `-new-9`/`-new-10` catalogued 2026-08-10. `simple-date-formatter-new-13@1.0.0` (GHSA-539g-4gx9-g555) is a bsrc-SSRF variant: postinstall `curl`s `bsrc-ssrf.n.baidu-int.com/6395292252` (an internal Baidu SSRF target) and exfils the response to `pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun/bsrc`. `simple-date-formatter-new-14@1.0.0` (GHSA-7r88-5m7v-8m5w) `nslookup`s `9e954818.log.dnslogs.dpdns.org` (dnslogs.dpdns.org OOB service) and separately HTTPS-POSTs SSH keys to `124.221.154.135`. `simple-date-formatter-new-15@1.0.0` (GHSA-fj2x-7537-68xm) is the same SSH-key + cloud-metadata payload as `-new-11` with `metadata.tencentyun.com` and `169.254.0.23` added and a placeholder host `YOUR_BURP_SERVER` left in the code (PoC/typosquat stub). The `124.221.154.135` IP has been operator infrastructure since at least 2026-08-10 (previous port `:4444`, current port `:443`)
- **Cluster H - npm `aliftech-ui`/`@birbalo/aliftech-ui` shared-`webhook.site` dep-confusion siblings**: `aliftech-ui@99.9.9` (GHSA-648v-rwj3-6j2f) and `@birbalo/aliftech-ui@99.9.9` (GHSA-383w-gxv7-cg2f). Both ship a `postinstall.js` that reads `os.hostname()` + `os.userInfo().username` and embeds those in the URL path of an HTTPS request to **the exact same collector**: `https://webhook.site/539f8bb9-497a-4104-92f7-f95a77204cc2/`. One operator running two lures - an unscoped `aliftech-ui` and a `@birbalo/`-scoped variant, both at sentinel dep-confusion version `99.9.9`. Amazon Inspector attribution. Aliftech is a real fintech vendor with a legitimate internal `aliftech-ui` design system - almost certainly a targeted dep-confusion attempt against that org
- **Cluster I - npm `@alphaspace/core` Yahoo-internal dep-confusion + Pipedream exfil + istio/yahoo DNS recon**: `@alphaspace/core@99.0.0`/`99.0.1`/`99.0.2` (GHSA-5qqj-qfpp-jfqw). Preinstall script POSTs a JSON payload with hostname + username + Node version + `package.json` contents + npm registry config to `https://f5778d1d81cc30c39dcdd0da5ca1d49a.m.pipedream.net`, then issues DNS lookups against **specific Yahoo internal hostnames** including `istio-system.prod1-gq1.omega.yahoo.com` and `buildr.corp.yahoo.com`, then HTTPS-GETs those hosts with `NODE_TLS_REJECT_UNAUTHORIZED=0` and captures the response bodies. Sentinel version `99.0.0`+ is the dep-confusion attention-getter; the specific Yahoo internal hostnames + `@alphaspace` scope target the Yahoo/Verizon Media internal build stack. Amazon Inspector hash: `42d10ba1427af01794dfb0a6b39a05f969547455e9d86d75f18601b1d035c507`. Whether this is a legitimate bug-bounty engagement or an attacker probing the same target, any lockfile hit at Yahoo/Apollo/Verizon Media should be treated as a real dep-confusion attempt against internal infra
- **Cluster J - npm `eslint-config-compact-base@1.0.0` AWS API Gateway CI reconnaissance (GHSA-ghfm-6qx4-q8p4)**: on `require()`, exfils OS platform, hostname, username, arch, Node version, CWD, and the CI env vars `CI` / `RUNNER_NAME` / `GITHUB_REPOSITORY` as query-string params to `https://cbrsuo9293.execute-api.us-east-1.amazonaws.com/c` (attacker-controlled API Gateway). Fires on module load, so lint runs inside CI trigger it. Hash `dbc01e3a8316b2d4e11b34a9c8cbe1cf5bd2af83a6a70052e40a22b54f13f78b`. Recon-only - platform+hostname+repo name, no secret material exfiltrated - but pairs the org name (`GITHUB_REPOSITORY`) with the CI runner identity, which is enough to target follow-on attacks against that repo
- **Cluster K - npm `c2-client@1.0.0` postinstall command channel (GHSA-h7qv-4h6m-4g2x)**: `postinstall: node setup.js` runs attacker-controlled code at install time under installer privileges. Advisory body is CWE-506 boilerplate without published IOC/payload analysis - treat as a probe or a lure whose payload was not captured. The name `c2-client` is unusually candid; likely a red-team artefact left published
- **Cluster L - pip `prosocks` proxy-network hijack campaign + `my-private-pkg` + `vercel-runtime-python` Vercel dep-confusion pentests**: pip `prosocks@1.0.0`-`1.0.9`/`1.0.13`-`1.0.23`/`1.0.25`-`1.0.32` (GHSA-6v7p-c53r-646f) contains embedded code that auto-joins the installer machine to a proxy network - a residential-proxy hijack that turns any developer or CI runner that ran `pip install prosocks` into an unwitting proxy exit node. Persistence + auto-run classification. Wide version range across ~30 published versions is unusual for a probe and consistent with an operator publishing successive builds of a working payload. pip `my-private-pkg@99.1.1` (GHSA-v7x9-wx5x-qrpp) is a Vercel dep-confusion lure whose install command collects `os.getlogin()`, `socket.gethostname()`, local IP, `os.getcwd()`, `platform.system()/machine()` and POSTs to `webhook.site/d4d1b01b-708a-40b9-b8c8-187eeecafeed`; the package also ships a `vercel_runtime_python` module name to mimic Vercel`s Python runtime. pip `vercel-runtime-python@0.1.0/99.99.99/100.99.99/100.100.99` (GHSA-fvc2-927p-99h8) is the sibling Vercel-runtime-Python dep-confusion probe: `setup.py` install override + import-time host exfil, classified `PROBABLY_PENTEST`. Both `my-private-pkg` and `vercel-runtime-python` target Vercel internal builds

## What to do

1. Grep every `package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`, `package.json`, `requirements.txt`, `Pipfile.lock`, `poetry.lock` in your org for every package name in Clusters A through L. Uninstall on hit, wipe `node_modules`/`.venv`, delete the lockfile, rebuild against a clean cache. Clusters A, B, C, D, E, F, G, H, I, J, and L all include confirmed real payloads (DNS-OOB exfil, mkicom.com binary dropper + magic-key RCE, JPEG-hidden Windows PowerShell dropper, Windows AES/ChaCha20 dropper, obfuscated fetch-and-execute, XOR Python dropper, SSH-key exfil to 124.221.154.135, webhook.site recon, Yahoo-targeted dep-confusion, CI recon, proxy-network hijack) - a hit on any of those is a compromise, not a warning
2. **For Cluster A (`@nf-addons/am-global-header` + `@osl-design/react` algamil7x day-7 late-adds)**: keep the `oob.algamil7x.xyz` resolver block in place from prior days (this is now day 7 confirmed with two late additions). The `.xyz` zone block is the durable mitigation because the operator picks a fresh internal-lookalike scope every 24 hours. If your org owns an `@nf-addons` or `@osl-design` scope internally, pin the legitimate scope in `.npmrc` to your private registry so the public malware cannot resolve preferentially. Rotate any credential accessible from a host that install-ran either package
3. **For Cluster B (`n8n-nodes-*` `mkicom.com` dropper family)**: uninstall on hit. Any self-hosted n8n runner that ran `npm install n8n-nodes-moonlet-helpers`, `n8n-nodes-moonlet-utils`, or `n8n-nodes-flowstats` in the last 48h has an attacker-controlled binary running as a detached background process - kill any process holding `/tmp/.np`, `/tmp/.nc`, `/tmp/.fs_dev`, or `/tmp/.fs_prod`, image the host if it faced the internet. For `n8n-nodes-flowstats` specifically, if the compromised node was ever mounted into an active n8n workflow with an HTTP-triggered endpoint, treat that workflow`s HTTP endpoint as an exposed `child_process.exec` gateway keyed on `k=kx9p26`. Block `mkicom.com` at your resolver AND at your web proxy; the `.well-known/pki-validation/` path was chosen to blend with ACME traffic so a path-based block is required. Block `104.21.3.16` at network egress
4. **For Cluster C (`secure-env3` + `better-dotenv3` JPEG-hidden dotenv dropper)**: uninstall on hit. On any Windows host that install-ran or import-ran either package, treat the box as compromised - the payload writes a self-deleting `.vbs` to `%TEMP%` and hands off to PowerShell so the disk artefact is gone by the time you look. Look at PowerShell script-block logging (Event ID 4104) and AMSI logs around the install time for encoded-command executions. Rotate any credential accessible to the local user account. Because the package.json is renamed internally (`better-dotenv3` publishes as `node-env-buffer@2.2.6`), pin your dotenv dependency to the specific real `dotenv` package by exact name in your lockfile and reject any resolution to `secure-env*`, `better-dotenv*`, or `node-env-buffer` variants
5. **For Cluster D (`agency-test-exercise` + `agency-testts` Windows AES/ChaCha20 dropper)**: uninstall on hit. Any Windows host that ran `npm install` on either package has run a random `.dat` file from `%TEMP%` through PowerShell + process hollowing - image the host, don`t attempt in-place cleanup. Look for a random-named `.dat` file created in `%TEMP%` around the install time and preserve it for analysis before wiping
6. **For Cluster E (`chromatitle` + `chromatitle-js` obfuscated fetch-and-execute)**: uninstall on hit. **`--ignore-scripts` does NOT block this family** - the fetch-and-execute chain fires when the module is required, not when it is installed. Any downstream package that transitively depends on either variant will trigger the payload at build time or import time. Grep your dep tree with `npm ls chromatitle chromatitle-js` and yank both from any lockfile they appear in. Block outbound HTTPS to any endpoint that shows up when you decode the string array - the runtime target is not visible in the static source
7. **For Cluster F (`wallet-connect-adapter` Windows Python dropper)**: uninstall on hit. Windows-only, install-script-triggered, so `--ignore-scripts` blocks new installs. Look for a Python `requests` install with no matching legitimate `requirements.txt` on any Windows host in the last 48h - it is the giveaway that this loader ran. Rotate any credential accessible to the installer user account and check for a hidden detached Python process
8. **For Cluster G (`simple-date-formatter-new-11/13/14/15` SSH-key + oast.fun continuation)**: block outbound to `124.221.154.135` (both `:443` and `:4444` from prior versions), `pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun`, and `9e954818.log.dnslogs.dpdns.org` at CI network egress. On any hit, rotate every SSH key in `~/.ssh` on the affected host - the attacker has the file listing at minimum and, for `-new-11`/`-14`/`-15`, the key filenames + username + platform. For `-new-13` specifically, if you run internal Baidu network infrastructure, review whether `bsrc-ssrf.n.baidu-int.com/6395292252` returned anything sensitive to the compromised host during the install window. The `-new-<NNN>` naming pattern is now a confirmed cross-month campaign; add a lockfile-lint rule that rejects any `simple-date-formatter-new-*` name outright
9. **For Cluster H (`aliftech-ui` + `@birbalo/aliftech-ui` webhook.site dep-confusion)**: uninstall on hit. If your org uses the legitimate Aliftech `aliftech-ui` design system internally, pin it in `.npmrc` to your private registry so the public sentinel `99.9.9` cannot resolve preferentially. Rotate no secrets (hostname + username only) but treat the presence of either package in a lockfile as evidence that the operator has probed for your internal-package name and expect follow-on attempts under a related name
10. **For Cluster I (`@alphaspace/core` Yahoo-internal dep-confusion)**: uninstall on hit. If you work on Yahoo/Apollo/Verizon Media internal infrastructure and the `@alphaspace/core` name appears in any lockfile, treat it as a real dep-confusion attempt against your build stack; contact security@yahoo. The `NODE_TLS_REJECT_UNAUTHORIZED=0` side-effect persists for the lifetime of any long-running Node process the package touched. Block `f5778d1d81cc30c39dcdd0da5ca1d49a.m.pipedream.net` at your network egress. Even if this is a legitimate bug-bounty engagement against Yahoo, the payload will still ship system metadata to the researcher`s Pipedream endpoint on every install
11. **For Cluster J (`eslint-config-compact-base` AWS API Gateway CI recon)**: uninstall on hit. Recon-only (`os.platform`/`os.hostname`/`os.userInfo`/`process.env.GITHUB_REPOSITORY` only, no secret material), but the operator now has your CI runner name paired with your public repo name and can target follow-on attempts. Block `cbrsuo9293.execute-api.us-east-1.amazonaws.com` at CI network egress. Do NOT commit the removal in the same PR as any other change - a subsequent commit reverting the removal would silently re-establish exfil
12. **For Cluster K (`c2-client` postinstall command channel)**: uninstall on hit. Payload is undocumented - treat as install-time compromise until you can inspect the tarball. Rotate any credential accessible from the install account
13. **For Cluster L (pip `prosocks` proxy-hijack + `my-private-pkg` + `vercel-runtime-python` Vercel dep-confusion)**: for `prosocks`, any dev workstation or CI runner that ran `pip install prosocks==<any version 1.0.0-1.0.32>` in the last two weeks is now an operator-controlled proxy exit node - image the host and rotate every credential visible to the installer user; **your outbound residential/CI IP is now attributable to third-party traffic sent through the proxy**, which is a legal + reputation exposure distinct from the credential-theft risk. For `my-private-pkg` and `vercel-runtime-python`, block `webhook.site/d4d1b01b-708a-40b9-b8c8-187eeecafeed` at your network egress; if you run Vercel internal infrastructure, pin the real `vercel_runtime_python` to your private registry
14. For every `npm install` in CI, prefer `--ignore-scripts` and enforce it at the runner level (note it does NOT block Clusters C or E - both fire at `require`/module-load, not on install script). Layer with egress denylists on `oob.algamil7x.xyz`, `mkicom.com` (including the fake `.well-known/pki-validation/` path), `104.21.3.16`, `124.221.154.135`, `pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun`, `9e954818.log.dnslogs.dpdns.org`, `webhook.site` (or specifically the two campaign paths listed above), `f5778d1d81cc30c39dcdd0da5ca1d49a.m.pipedream.net`, and `cbrsuo9293.execute-api.us-east-1.amazonaws.com`. Extend the pin-lists from prior sweeps with `@nf-addons/am-global-header`, `@osl-design/react`, `n8n-nodes-moonlet-helpers`, `n8n-nodes-moonlet-utils`, `n8n-nodes-flowstats`, `secure-env3`, `better-dotenv3`, `agency-test-exercise`, `agency-testts`, `chromatitle`, `chromatitle-js`, `wallet-connect-adapter`, `simple-date-formatter-new-11`, `simple-date-formatter-new-13`, `simple-date-formatter-new-14`, `simple-date-formatter-new-15`, `aliftech-ui`, `@birbalo/aliftech-ui`, `@alphaspace/core`, `eslint-config-compact-base`, `c2-client`, pip `prosocks`, pip `my-private-pkg`, pip `vercel-runtime-python`

## Check your own dependencies

- Check a package-lock.json against this incident: https://dependencywatch.io/check/package-lock-json
- Check a requirements.txt against this incident: https://dependencywatch.io/check/requirements-txt

The scan runs entirely in the browser; lockfile contents are never uploaded.

## References

- [GitHub Advisory Database - recent malware advisories](https://github.com/advisories?query=type%3Amalware&sort=published-desc) - GitHub
- [GHSA-hj7v-p563-fffq - @nf-addons/am-global-header (Cluster A - algamil7x day-7 late-add)](https://github.com/advisories/GHSA-hj7v-p563-fffq) - GitHub
- [GHSA-qx4v-776h-xcpw - @osl-design/react (Cluster A - algamil7x day-7 late-add, prefix `osldr`)](https://github.com/advisories/GHSA-qx4v-776h-xcpw) - GitHub
- [GHSA-hh4f-fhfw-7vgw - n8n-nodes-moonlet-helpers (Cluster B - mkicom.com dropper via /.well-known/pki-validation/ct_pn8)](https://github.com/advisories/GHSA-hh4f-fhfw-7vgw) - GitHub
- [GHSA-f77h-w3rc-2c74 - n8n-nodes-moonlet-utils (Cluster B - mkicom.com dropper via /.well-known/pki-validation/ct_dn8)](https://github.com/advisories/GHSA-f77h-w3rc-2c74) - GitHub
- [GHSA-wm7h-qmp4-782c - n8n-nodes-flowstats (Cluster B - 104.21.3.16 Host:mkicom.com + magic-key kx9p26 RCE)](https://github.com/advisories/GHSA-wm7h-qmp4-782c) - GitHub
- [GHSA-w2g5-xcc6-p474 - secure-env3 (Cluster C - JPEG APP14 hidden VBS/PowerShell dropper)](https://github.com/advisories/GHSA-w2g5-xcc6-p474) - GitHub
- [GHSA-qx8m-mvxg-49m3 - better-dotenv3 (Cluster C - JPEG APP13 hidden VBS/PowerShell dropper, node-env-buffer alias)](https://github.com/advisories/GHSA-qx8m-mvxg-49m3) - GitHub
- [GHSA-qwj9-hfhg-j6vh - agency-test-exercise (Cluster D - wscript.exe 4444.vbs AES+ChaCha20 dropper)](https://github.com/advisories/GHSA-qwj9-hfhg-j6vh) - GitHub
- [GHSA-75mh-8gwp-9cvf - agency-testts (Cluster D - wscript.exe 4444.vbs AES dropper)](https://github.com/advisories/GHSA-75mh-8gwp-9cvf) - GitHub
- [GHSA-7pgp-qm32-53rp - chromatitle (Cluster E - obfuscated fetch-and-execute ANSI-color lure)](https://github.com/advisories/GHSA-7pgp-qm32-53rp) - GitHub
- [GHSA-93mr-5j8f-6p3w - chromatitle-js (Cluster E - obfuscated fetch-and-execute sibling)](https://github.com/advisories/GHSA-93mr-5j8f-6p3w) - GitHub
- [GHSA-39rm-rv2w-366r - wallet-connect-adapter (Cluster F - Windows XOR-encrypted Python dropper)](https://github.com/advisories/GHSA-39rm-rv2w-366r) - GitHub
- [GHSA-2v58-3f75-j4jv - simple-date-formatter-new-11 (Cluster G - 124.221.154.135:443 SSH-key + oast.fun)](https://github.com/advisories/GHSA-2v58-3f75-j4jv) - GitHub
- [GHSA-539g-4gx9-g555 - simple-date-formatter-new-13 (Cluster G - Baidu BSRC SSRF + oast.fun)](https://github.com/advisories/GHSA-539g-4gx9-g555) - GitHub
- [GHSA-7r88-5m7v-8m5w - simple-date-formatter-new-14 (Cluster G - dnslogs.dpdns.org + 124.221.154.135 SSH-key)](https://github.com/advisories/GHSA-7r88-5m7v-8m5w) - GitHub
- [GHSA-fj2x-7537-68xm - simple-date-formatter-new-15 (Cluster G - 124.221.154.135 SSH-key stub)](https://github.com/advisories/GHSA-fj2x-7537-68xm) - GitHub
- [GHSA-648v-rwj3-6j2f - aliftech-ui (Cluster H - webhook.site/539f8bb9-... dep-confusion)](https://github.com/advisories/GHSA-648v-rwj3-6j2f) - GitHub
- [GHSA-383w-gxv7-cg2f - @birbalo/aliftech-ui (Cluster H - same webhook.site UUID as aliftech-ui)](https://github.com/advisories/GHSA-383w-gxv7-cg2f) - GitHub
- [GHSA-5qqj-qfpp-jfqw - @alphaspace/core (Cluster I - Yahoo internal dep-confusion + Pipedream + istio/yahoo DNS recon)](https://github.com/advisories/GHSA-5qqj-qfpp-jfqw) - GitHub
- [GHSA-ghfm-6qx4-q8p4 - eslint-config-compact-base (Cluster J - AWS API Gateway CI env-var recon)](https://github.com/advisories/GHSA-ghfm-6qx4-q8p4) - GitHub
- [GHSA-h7qv-4h6m-4g2x - c2-client (Cluster K - postinstall command channel)](https://github.com/advisories/GHSA-h7qv-4h6m-4g2x) - GitHub
- [GHSA-6v7p-c53r-646f - prosocks pip (Cluster L - proxy-network hijack, 2026-09-prosocks campaign)](https://github.com/advisories/GHSA-6v7p-c53r-646f) - GitHub
- [GHSA-v7x9-wx5x-qrpp - my-private-pkg pip (Cluster L - vercel_runtime_python dep-confusion / webhook.site)](https://github.com/advisories/GHSA-v7x9-wx5x-qrpp) - GitHub
- [GHSA-fvc2-927p-99h8 - vercel-runtime-python pip (Cluster L - Vercel dep-confusion, PROBABLY_PENTEST)](https://github.com/advisories/GHSA-fvc2-927p-99h8) - GitHub
- [jaschadub/compromised-packages-check](https://github.com/jaschadub/compromised-packages-check) - jaschadub
- [OpenSSF malicious-packages repository](https://github.com/ossf/malicious-packages) - OpenSSF

---

Canonical page: https://dependencywatch.io/incident/multi-2026-09-25-ghsa-malware-sweep
Markdown version: https://dependencywatch.io/incident/multi-2026-09-25-ghsa-malware-sweep.md
Site index for agents: https://dependencywatch.io/llms.txt
DependencyWatch.io is operated by Precursor Security (https://precursorsecurity.com).
