GitHub Advisory malware sweep - 2026-09-26 (late) + 2026-09-27 (pip `donutautosellsrc` steganographic infostealer + Polygon-blockchain C2 resolver; pip `requests-cache-utils` `setup.py` remote-EXE downloader/browser-data infostealer; npm `chai-as-relay` `pino` impersonator with 4.4MB obfuscated IIFE loaded on import; npm `cma-self-hosted-sandbox-cf` preinstall `/etc/passwd`+`/etc/hosts`+DNS recon exfil to `oastify.com` OOB. No fresh `ltidi.storage.googleapis.com` or `algamil7x` variants in the window)
GHSA 2026-09-26 (late) + 2026-09-27: 4 new advisories - 2 pip + 2 npm not caught by yesterdays sweep. Worst confirmed items are pip donutautosellsrc (steganographic loader + Polygon-blockchain-resolved C2 + native infostealer) and pip requests-cache-utils (setup.py-installed remote EXE + browser data exfil). npm chai-as-relay impersonates pino and loads a 4.4MB obfuscated IIFE on import. npm cma-self-hosted-sandbox-cf preinstall harvests /etc/passwd+/etc/hosts`+DNS config to a Burp Collaborator OOB host.
- Incident type
- Advisory sweep. A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
- Detected by
- GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · Amazon Inspector · kam193/bad-packages
- Also known as
- 2026-09-27 GHSA npm+pip sweep · donutautosellsrc pip steganography + Polygon blockchain C2 · requests-cache-utils pip setup.py remote EXE · chai-as-relay npm pino impersonator 4.4MB IIFE · cma-self-hosted-sandbox-cf npm preinstall /etc/passwd recon
- Ecosystems
- npmPyPI
- Packages tracked
- 4
What happened
Between roughly 2026-09-26 12:00 UTC and 2026-09-27 12:00 UTC, the GitHub Advisory Database (plus the OpenSSF malicious-packages bulk export, Amazon Inspector`s IN-MAL feed, and kam193/bad-packages) published 4 new malware advisories the 2026-09-26 sweep did not catch: 2 pip and 2 npm. All 4 carry fully-analysed real payloads or fully-attributed recon behaviour; no CWE-506-boilerplate-only takedowns this window.
Cluster A - pip donutautosellsrc steganography + Polygon-blockchain C2 + native infostealer
donutautosellsrc@0.3.7/0.3.8/0.3.9 (GHSA-2w77-qp99-3jvq, MAL-2026-17192, OpenSSF campaign 2026-09-donutautosellsrc). Three related primitives:
- Steganography - the payload retrieves an image (
https://thisisafalsepositive.st/cdn/v2/9f4e7a2c1b8d.png, itself a taunt at antivirus scanners) with the real executable bytes hidden inside the image data. Downloading a PNG through a CDN looks nothing like malware transfer to network telemetry. - Native extension modules - the payload drops compiled Python C-extension
.so/.pydfiles that carry the obfuscated infostealer. Static analysis on.sois materially harder than on Python source, and native code sidesteps any interpreter-level defence you might have (e.g.python-audithooks). - Blockchain-resolved C2 - the malware does not hard-code a C2 hostname. Instead it queries a public Polygon RPC endpoint for the transaction history of attacker-controlled wallet
0x9c0a507300fd902787bb193d80fca5ce6e1bff9aand parses out the C2 endpoint from transaction metadata. This is the most defensively interesting bit: as long as the operator can broadcast a fresh Polygon transaction (which costs cents), they rotate C2 without touching DNS, and every defender relying on domain-level egress lists is now watching the wrong layer.
Observed IOCs beyond the wallet and image URL: secondary domain sltnnt.ru. Payload hash d03c42c275f0dbc617428441508c49ae1adcbbc95af4eeb094bca4e4f8943f3e; dropper hash 2ac1203ac68b4bb062c4dd38f59fd8bd13fef695c5b1c8059160c6a5205717b1.
The name has no legitimate namesake in the corpus and reads as a lure aimed at donation/autosell tooling for something specific (crypto-adjacent). Classify as malicious-package.
Cluster B - pip requests-cache-utils install-time remote EXE
requests-cache-utils@1.0.0 (GHSA-mc8h-7wqw-2mcf, MAL-2026-17191, OpenSSF campaign 2026-09-requests-cache-utils). Overrides setup.py install to run at install time, and additionally the payload executes at module import time. On install:
- Downloads
http://104.234.65.75:700/setup.exe(plain HTTP, non-standard high port - both features an existing egress policy may catch if it enforces port-80/443-only or TLS-only outbound). - Executes the fetched EXE. Per kam193 analysis, the EXE is a browser-data infostealer.
The name is a plausible typosquat of the legitimate requests-cache package (a real HTTP-response cache for requests). A developer searching for "requests cache util" may reach for the public registry and land on this by mistake. Hashes: source 1655ea47fc7ccd39294203776ee3dcb01a394c40d93e05b7b527700b19de42c8; VirusTotal-observed sample 274c2b93e3c6ca726f21d02f6a8e3602853dbe775a122f5510c42f1d491995a3.
Classify as malicious-package (typosquat with real remote-code payload).
Cluster C - npm chai-as-relay pino impersonator with 4.4MB obfuscated IIFE
chai-as-relay@1.2.1 (GHSA-mq79-xj84-m775, MAL-2026-17189). Impersonates the legitimate pino logger project - the README borrows pinos keywords, feature bullets, and stated capabilities - while the modules index.js` loads a heavily-obfuscated ~4.4 MB blob at module initialisation. The blob is:
- Immediately-Invoked Function Expression (IIFE), so it runs on first evaluation, not on an exported call
- Hex-escaped string arrays
- Control-flow flattening (opaque predicates, chained switch statements)
At 4.4 MB of obfuscated JS the payload is too large for meaningful adversarial static analysis in the general case; treat as opaque hostile code. The module additionally exports a single no-op middleware to keep basic static analysis quiet.
Because the payload fires on require()/import (not only on npm install), a lockfile scan alone is not enough - grep your codebase for chai-as-relay in source, tests, and transitively-generated code, and revert any add that was not authored by a known human on your team.
Package author hello@jsonspack.com. IOCs: tarball SHA1 b78835bcec5b368ed0695706aa6eb15ab0c80a1b, tarball SHA512 SRI sha512-Gzsi2w4ZEctlgEoQLU5pWM9oD/wKesHwq0uy3SC8wKcvJoLHFcvzvhtAAdQwqueChEII6ZTkaqQYE3XKY2h51Q==, package.json SHA256 37af31772ae215ad9ab85f2f37a7c46cbec4bb7b0a10ae13b7b4f19b84778a84, lib/config.js SHA256 cc93ac7310b3a044badfc17f112a763bb24452ca88236892a470fdd362a9af36, source SHA256 5c65319b0e17f945fc57f482eb174e5d7fe70e63a380cb24f64eea1808bdad2f. Detected by Amazon Inspector.
Name choice ("chai-as-relay") reads as a chai+chai-as-promised-family test-utility - so the impersonation lure targets developers wiring test tooling, not observability tooling directly. Classify as malicious-package (impersonation lure with real payload).
Cluster D - npm cma-self-hosted-sandbox-cf preinstall /etc/passwd+/etc/hosts+DNS recon to Burp Collaborator OOB
cma-self-hosted-sandbox-cf@<=1.0.0 (GHSA-wjmh-pc3x-575f, MAL-2026-17190). Preinstall lifecycle hook automatically runs index.js, which harvests:
os.hostname()and the user identity block (uid/gid/username/home)/etc/resolv.conf(DNS resolver configuration)/etc/passwd(full user/service-account list on the host)/etc/hosts(any internal-DNS overrides or pinned addresses)
…and POSTs the bundle over HTTPS to 49bl3t5yt786ymbtth24nnlbs2ytmka9.oastify.com.
.oastify.com is a Burp Collaborator out-of-band interaction domain - the same class as .oast.fun and .interactsh.com. Both authorised pentesters and unauthorised opportunistic actors use it, so the exfil endpoint alone does not tell you which. /etc/passwd and /etc/hosts are not secrets in themselves, but they reveal service accounts and internal DNS pins that materially help a follow-on stage. The cma-self-hosted-sandbox-cf name (cma + self-hosted-sandbox + -cf for Cloudflare) reads as an internal CI sandbox package, so the attempt is directed at an org that runs a private cma-self-hosted-sandbox-* scope internally - a dep-confusion probe.
IOCs: index.js SHA256 fa43f4bd7d96ea8586808a750372d218b48a3a0bf0943f1310cf296b77e52305, tarball SHA1 83157fa69aa97b8d23922b3c72d352429c142f10, tarball SHA512 SRI sha512-qRbU3aMPgajHHxrME++GmSoMK2L8vXsmvNTve0OHPFOLT9dKoIZoNT22w6Q2W/jAJwG5IgCzGO61AxTzXzkaQg==.
Classify as dependency-confusion (sentinel-name probe with recon payload, no confirmed secret exfil beyond /etc/passwd+/etc/hosts).
Operator continuity check
ltidi.storage.googleapis.com(yesterdays Cluster D@airbnb-extended/typescript-configGCS-tarball loader): no fresh@airbnb-extended/,ltidisafe`, or other GCS-tarball-loader manifests in this window. Egress block remains durable.oob.algamil7x.xyz: no fresh day-9 additions in this window..xyzegress block remains durable on the multi-day pattern.eo8f3m3ho26a0nm.m.pipedream.net(yesterdays Cluster Eshoplist-app`): no new packages beaconing to this Pipedream endpoint.simple-date-formatter-new-<N>(124.221.154.135SSH-beacon family): no-new-12/-16/higher today. Block remains durable.- *`n8n-nodes-
mkicom.com`**: no new packages. Block remains durable.
Five consecutive-day operators tracked earlier this week all show a one-to-two-day pause in this window - do not remove the blocks on that basis.
Registry state
All 4 packages in this sweep are npm/pip-quarantined at time of writing. Active operator-side infrastructure unique to today`s batch:
thisisafalsepositive.st+sltnnt.ru(Cluster A steganography and secondary)- Polygon wallet
0x9c0a507300fd902787bb193d80fca5ce6e1bff9a(Cluster A blockchain C2 lookup) 104.234.65.75:700(Cluster B remote EXE)49bl3t5yt786ymbtth24nnlbs2ytmka9.oastify.com(Cluster D Burp Collaborator OOB)
Discovery credits
GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector, kam193/bad-packages. Per-package IOC details drawn from GHSA and OSSF advisory bodies published between 2026-09-26 12:00 UTC and 2026-09-27 12:00 UTC.
Affected packages (4)
- npmchai-as-relay1.2.1
- npmcma-self-hosted-sandbox-cf1.0.0
- PyPIdonutautosellsrc0.3.70.3.80.3.9
- PyPIrequests-cache-utils1.0.0
These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.
Impact
- Cluster A - pip
donutautosellsrcsteganographic loader + Polygon-blockchain C2 + native infostealer (real payload):donutautosellsrc@0.3.7/0.3.8/0.3.9(GHSA-2w77-qp99-3jvq, MAL-2026-17192, OSSF campaign2026-09-donutautosellsrc). Novel-for-this-corpus primitive stack: at install time the package (i) retrieves a remote executable whose payload is embedded in image data using steganography, (ii) drops native (compiled C-extension) Python modules that carry the obfuscated infostealer, and (iii) does not hard-code any C2 hostname - instead it reads command-and-control server addresses from Polygon blockchain transaction history for a specific attacker-controlled wallet, which defeats DNS-based egress denylists because the "C2 address" is fetched from a public blockchain RPC. Observed IOCs: steganography-carrier URLhttps://thisisafalsepositive.st/cdn/v2/9f4e7a2c1b8d.png, secondary domainsltnnt.ru, Polygon wallet0x9c0a507300fd902787bb193d80fca5ce6e1bff9a. Hashesd03c42c275f0dbc617428441508c49ae1adcbbc95af4eeb094bca4e4f8943f3e(payload) and2ac1203ac68b4bb062c4dd38f59fd8bd13fef695c5b1c8059160c6a5205717b1(dropper) - Cluster B - pip
requests-cache-utilsinstall-time + import-time remote EXE downloader + browser infostealer (real payload):requests-cache-utils@1.0.0(GHSA-mc8h-7wqw-2mcf, MAL-2026-17191, OSSF campaign2026-09-requests-cache-utils). Overridessetup.py installto run at install time, and additionally executes at module import time. Downloads a Windows PE fromhttp://104.234.65.75:700/setup.exeand executes it; the remote EXE is a browser-data infostealer per kam193 analysis. Name is a plausible typosquat of the legitimaterequests-cacheandrequestsfamily - a developer looking for a cache utility for therequestslibrary may reach for this by name. Because the install hook runs onpip install, no explicitimportis needed for the payload to fire - a lockfile hit is enough to have downloaded and executed the remote EXE. Hashes1655ea47fc7ccd39294203776ee3dcb01a394c40d93e05b7b527700b19de42c8(source),274c2b93e3c6ca726f21d02f6a8e3602853dbe775a122f5510c42f1d491995a3(VirusTotal-observed sample) - Cluster C - npm
chai-as-relaypinoimpersonator with 4.4MB obfuscated IIFE loaded at module init (real payload, malicious-package):chai-as-relay@1.2.1(GHSA-mq79-xj84-m775, MAL-2026-17189). Impersonates the legitimatepinologger project (the README, keywords, and stated capabilities crib frompino) while the modulesindex.jsloads a heavily-obfuscated ~4.4 MB blob at module initialisation - an IIFE with hex-escaped string arrays and control-flow flattening, no source-mapped provenance. Exports a single no-op middleware to keep static analysis quiet. The payload fires onrequire('chai-as-relay')orimport 'chai-as-relay'- not just on install - so a project that adds it as a dependency but never runsnpm installon the affected host is still executing arbitrary code the first time application code touches it. Package authorhello@jsonspack.com. IOCs: tarball SHA1b78835bcec5b368ed0695706aa6eb15ab0c80a1b, package.json SHA25637af31772ae215ad9ab85f2f37a7c46cbec4bb7b0a10ae13b7b4f19b84778a84, lib/config.js SHA256cc93ac7310b3a044badfc17f112a763bb24452ca88236892a470fdd362a9af36, source SHA2565c65319b0e17f945fc57f482eb174e5d7fe70e63a380cb24f64eea1808bdad2f`. Detected by Amazon Inspector - Cluster D - npm
cma-self-hosted-sandbox-cfpreinstall Burp-Collaborator recon exfil (real payload, dep-confusion / recon):cma-self-hosted-sandbox-cf@<=1.0.0(GHSA-wjmh-pc3x-575f, MAL-2026-17190). Preinstall lifecycle hook automatically runsindex.js, which collects hostname, user identity (uid/gid/username/home), DNS resolver configuration, and the full contents of/etc/passwdand/etc/hosts, then POSTs the bundle over HTTPS to49bl3t5yt786ymbtth24nnlbs2ytmka9.oastify.com. The.oastify.comFQDN is a Burp Collaborator out-of-band interaction host - a hallmark of authorised pentest / bug-bounty tooling, though the same infrastructure is also used opportunistically by non-authorised actors./etc/passwdand/etc/hostsare not secrets in themselves but reveal user accounts (_service accounts and their homes) and internal-DNS overrides (staging hostnames, internal IPs) that materially help follow-on targeting. Thecma-self-hosted-sandbox-cfname reads as an internal-CI sandbox package (Cloudflare/CMA-flavoured) so treat as a dep-confusion probe against an org that runs a privatecma-self-hosted-sandbox-*scope internally. Hashesfa43f4bd7d96ea8586808a750372d218b48a3a0bf0943f1310cf296b77e52305(index.js),83157fa69aa97b8d23922b3c72d352429c142f10(tarball SHA1) - Update 2026-09-28 - Cluster A
donutautosellsrccampaign extends to 4 more pip packages under the same wallet:aseity@0.1.0,coinscan@0.1.0,donutpromotion@<=0.1.0,claudedashbord@0.1.0-0.1.3were quarantined on 2026-09-27 (late) sharing the exact same payload hashd03c42c275f0dbc617428441508c49ae1adcbbc95af4eeb094bca4e4f8943f3eand attacker wallet0x9c0a507300fd902787bb193d80fca5ce6e1bff9a. See the 2026-09-28 sweep Cluster A for the extension detail - this is one operator scaling a name catalogue, not four independent copycats - Operator continuity check -
ltidi.storage.googleapis.comday-2 status (Cluster D from yesterday`s sweep): no fresh@airbnb-extended/*,ltidisafe*, or other GCS-tarball-loader manifests appeared in the 2026-09-27 window. Theltidi.storage.googleapis.comegress block from yesterday remains the durable mitigation. Similarly no freshoob.algamil7x.xyzday-9 additions, no newsimple-date-formatter-new-<N>versions, no freshn8n-nodes-*mkicom.comvariants, no new124.221.154.135SSH-beacon packages, and no newPipedreameo8f3m3ho26a0nm.m.pipedream.netbeacon packages - all five multi-day operators tracked over the last week are quiet in this window. The three network blocks (ltidi.storage.googleapis.com,oob.algamil7x.xyz,eo8f3m3ho26a0nm.m.pipedream.net) remain durable and should NOT be relaxed on a one-to-two-day quiet
What to do
- 1Grep every
package-lock.json,yarn.lock,pnpm-lock.yaml,package.json,requirements.txt,Pipfile.lock,poetry.lock, andpyproject.tomlfor every package name in Clusters A through D. Uninstall on hit, wipenode_modules/.venv, delete the lockfile, rebuild against a clean cache. Clusters A, B, and C each contain confirmed real payloads (steganographic + blockchain-C2 infostealer, remote EXE downloader/browser stealer, and a 4.4MB obfuscated on-import loader); a hit on any of those is a compromise, not a warning - 2For Cluster A (pip
donutautosellsrcsteganographic + Polygon-blockchain C2): uninstall on hit and image the host - the native-extension infostealer landed compiled C code on the host, so what a defender sees on disk today may not be the full payload. Rotate every credential the installer user account had access to (browser-saved passwords, wallet extensions, SSH keys, cloud CLI credentials, hardcoded env vars). Because the C2 addresses are fetched from a public Polygon RPC lookup against wallet0x9c0a507300fd902787bb193d80fca5ce6e1bff9arather than a fixed DNS entry, a domain-only egress denylist is not enough - either block the specific IOC domains (thisisafalsepositive.st,sltnnt.ru,.stand.ruTLDs if you can tolerate the false-positive rate) OR block outbound Polygon RPC endpoints (polygon-rpc.com,rpc-mainnet.matic.network,polygon-mainnet.g.alchemy.com,polygon-mainnet.infura.io, common public RPCs) from build/CI networks. Add a lockfile-lint rule that rejectsdonutautosellsrcoutright - 3For Cluster B (pip
requests-cache-utilsinstall-time remote EXE): uninstall on hit. On any Windows host or Wine-enabled Linux runner that ranpip install requests-cache-utils, assumesetup.exefrom104.234.65.75:700executed - treat the host as compromised, rotate every browser-saved credential, log out of every browser session, revoke every OAuth grant on your identity providers. Block104.234.65.75at network egress. If your team also uses the legitimaterequests-cachepackage, add a lockfile-lint rule that explicitly rejectsrequests-cache-utilsgiven the extreme name-collision risk. Adoptpip install --no-depsfor any install of an unverified package - 4For Cluster C (npm
chai-as-relaypinoimpersonator, on-import 4.4MB blob): uninstall on hit. Because the payload fires onrequire()/importrather than only on install, a lockfile scan alone is not enough - grep your codebase forchai-as-relay(in source, in tests, in transitively-generated code) and revert any add that was not authored by a known human on your team. Assume the module ran the first time the affected process started; rotate everything that process had in memory (credentials the app read from env vars, session cookies it held, DB connection strings). The 4.4MB obfuscated IIFE is too large for meaningful adversarial static analysis in the general case; treat as opaque hostile code. Add a lockfile-lint rule that rejects any dependency whose maintainer email ishello@jsonspack.com - 5For Cluster D (npm
cma-self-hosted-sandbox-cfpreinstall recon): uninstall on hit. Recon-only in payload (no secret material beyond/etc/passwd+/etc/hosts+DNS config), but the operator now has a partial map of your host: usernames, service accounts, internal-DNS overrides, and DNS-resolver configuration. Block49bl3t5yt786ymbtth24nnlbs2ytmka9.oastify.comat network egress and (if operationally tolerable) block*.oastify.comand*.oast.funoutright from build/CI networks - both are Burp Collaborator zones that legitimate first-party code has no reason to reach. If your org has an internalcma-self-hosted-sandbox-*scope, pin the internal version in.npmrcso the public sentinel cannot resolve preferentially - 6For every
npm installin CI, prefer--ignore-scriptsand enforce it at the runner level, and for everypip install, prefer resolving from a curated internal mirror rather than PyPI directly. Reject npm dependencies whose resolved URL is nothttps://registry.npmjs.org/*or your private registry (this catches yesterdaysltidi.storage.googleapis.comtarball loader and any future GCS/S3 tarball dep). Extend the pin-lists from prior sweeps withdonutautosellsrc,requests-cache-utils(pip), andchai-as-relay,cma-self-hosted-sandbox-cf(npm). Keep theltidi.storage.googleapis.com,oob.algamil7x.xyz,eo8f3m3ho26a0nm.m.pipedream.net,mkicom.com,104.21.3.16,124.221.154.135, andpdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun` blocks from prior days in place - the operators are quiet in the 2026-09-27 window but the blocks are durable
References
- GitHubGitHub Advisory Database - recent malware advisoriesgithub.com
- GitHubGHSA-2w77-qp99-3jvq - pip donutautosellsrc (Cluster A - steganography + Polygon-blockchain C2 + native infostealer, MAL-2026-17192)github.com
- GitHubGHSA-mc8h-7wqw-2mcf - pip requests-cache-utils (Cluster B - setup.py remote-EXE downloader + browser infostealer, MAL-2026-17191)github.com
- GitHubGHSA-mq79-xj84-m775 - npm chai-as-relay (Cluster C - pino impersonator, 4.4MB obfuscated IIFE on import, MAL-2026-17189)github.com
- GitHubGHSA-wjmh-pc3x-575f - npm cma-self-hosted-sandbox-cf (Cluster D - preinstall /etc/passwd+/etc/hosts recon to oastify.com OOB, MAL-2026-17190)github.com
- OpenSSFOSSF malicious-packages - MAL-2026-17192 donutautosellsrcgithub.com
- OpenSSFOSSF malicious-packages - MAL-2026-17191 requests-cache-utilsgithub.com
- OpenSSFOSSF malicious-packages - MAL-2026-17189 chai-as-relaygithub.com
- OpenSSFOSSF malicious-packages - MAL-2026-17190 cma-self-hosted-sandbox-cfgithub.com