# GitHub Advisory malware sweep - 2026-09-26 (late) + 2026-09-27 (pip `donutautosellsrc` steganographic infostealer + Polygon-blockchain C2 resolver; pip `requests-cache-utils` `setup.py` remote-EXE downloader/browser-data infostealer; npm `chai-as-relay` `pino` impersonator with 4.4MB obfuscated IIFE loaded on import; npm `cma-self-hosted-sandbox-cf` preinstall `/etc/passwd`+`/etc/hosts`+DNS recon exfil to `oastify.com` OOB. No fresh `ltidi.storage.googleapis.com` or `algamil7x` variants in the window)

> GHSA 2026-09-26 (late) + 2026-09-27: 4 new advisories - 2 pip + 2 npm not caught by yesterday`s sweep. Worst confirmed items are pip `donutautosellsrc` (steganographic loader + Polygon-blockchain-resolved C2 + native infostealer) and pip `requests-cache-utils` (`setup.py`-installed remote EXE + browser data exfil). npm `chai-as-relay` impersonates `pino` and loads a 4.4MB obfuscated IIFE on import. npm `cma-self-hosted-sandbox-cf` preinstall harvests `/etc/passwd`+`/etc/hosts`+DNS config to a Burp Collaborator OOB host.

- Published: 2026-09-27
- Last updated: 2026-09-28
- Severity: high
- Kind: Advisory sweep - A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
- Ecosystems: npm, PyPI
- Scope: 4 packages, 6 compromised versions
- Tags: infostealer, credential-theft, obfuscation, typosquat, dependency-confusion, dns-exfiltration, ci-cd-compromise
- Also known as: 2026-09-27 GHSA npm+pip sweep, donutautosellsrc pip steganography + Polygon blockchain C2, requests-cache-utils pip setup.py remote EXE, chai-as-relay npm pino impersonator 4.4MB IIFE, cma-self-hosted-sandbox-cf npm preinstall /etc/passwd recon
- Detected by: GitHub Advisory Database, OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector, kam193/bad-packages
- Incident ID: multi-2026-09-27-ghsa-malware-sweep

## Affected packages (4)

Only the exact versions listed were named by the source advisories. Other versions are not implicated.

| Package | Ecosystem | Compromised versions |
|---|---|---|
| [chai-as-relay](https://dependencywatch.io/package/npm/chai-as-relay) | npm | 1.2.1 |
| [cma-self-hosted-sandbox-cf](https://dependencywatch.io/package/npm/cma-self-hosted-sandbox-cf) | npm | 1.0.0 |
| [donutautosellsrc](https://dependencywatch.io/package/pypi/donutautosellsrc) | PyPI | 0.3.7, 0.3.8, 0.3.9 |
| [requests-cache-utils](https://dependencywatch.io/package/pypi/requests-cache-utils) | PyPI | 1.0.0 |

## What happened

Between roughly 2026-09-26 12:00 UTC and 2026-09-27 12:00 UTC, the GitHub Advisory Database (plus the OpenSSF malicious-packages bulk export, Amazon Inspector`s IN-MAL feed, and kam193/bad-packages) published 4 new malware advisories the [2026-09-26 sweep](https://dependencywatch.io/incident/multi-2026-09-26-ghsa-malware-sweep) did not catch: 2 pip and 2 npm. All 4 carry fully-analysed real payloads or fully-attributed recon behaviour; no CWE-506-boilerplate-only takedowns this window.

## Cluster A - pip `donutautosellsrc` steganography + Polygon-blockchain C2 + native infostealer

`donutautosellsrc@0.3.7/0.3.8/0.3.9` (GHSA-2w77-qp99-3jvq, MAL-2026-17192, OpenSSF campaign `2026-09-donutautosellsrc`). Three related primitives:

1. **Steganography** - the payload retrieves an image (`https://thisisafalsepositive.st/cdn/v2/9f4e7a2c1b8d.png`, itself a taunt at antivirus scanners) with the real executable bytes hidden inside the image data. Downloading a PNG through a CDN looks nothing like malware transfer to network telemetry.
2. **Native extension modules** - the payload drops compiled Python C-extension `.so`/`.pyd` files that carry the obfuscated infostealer. Static analysis on `.so` is materially harder than on Python source, and native code sidesteps any interpreter-level defence you might have (e.g. `python-audit` hooks).
3. **Blockchain-resolved C2** - the malware does not hard-code a C2 hostname. Instead it queries a public Polygon RPC endpoint for the transaction history of attacker-controlled wallet `0x9c0a507300fd902787bb193d80fca5ce6e1bff9a` and parses out the C2 endpoint from transaction metadata. This is the most defensively interesting bit: as long as the operator can broadcast a fresh Polygon transaction (which costs cents), they rotate C2 without touching DNS, and every defender relying on domain-level egress lists is now watching the wrong layer.

Observed IOCs beyond the wallet and image URL: secondary domain `sltnnt.ru`. Payload hash `d03c42c275f0dbc617428441508c49ae1adcbbc95af4eeb094bca4e4f8943f3e`; dropper hash `2ac1203ac68b4bb062c4dd38f59fd8bd13fef695c5b1c8059160c6a5205717b1`.

The name has no legitimate namesake in the corpus and reads as a lure aimed at donation/autosell tooling for something specific (crypto-adjacent). Classify as `malicious-package`.

## Cluster B - pip `requests-cache-utils` install-time remote EXE

`requests-cache-utils@1.0.0` (GHSA-mc8h-7wqw-2mcf, MAL-2026-17191, OpenSSF campaign `2026-09-requests-cache-utils`). Overrides `setup.py install` to run at install time, and additionally the payload executes at module import time. On install:

1. Downloads `http://104.234.65.75:700/setup.exe` (plain HTTP, non-standard high port - both features an existing egress policy may catch if it enforces port-80/443-only or TLS-only outbound).
2. Executes the fetched EXE. Per kam193 analysis, the EXE is a browser-data infostealer.

The name is a plausible typosquat of the legitimate `requests-cache` package (a real HTTP-response cache for `requests`). A developer searching for "requests cache util" may reach for the public registry and land on this by mistake. Hashes: source `1655ea47fc7ccd39294203776ee3dcb01a394c40d93e05b7b527700b19de42c8`; VirusTotal-observed sample `274c2b93e3c6ca726f21d02f6a8e3602853dbe775a122f5510c42f1d491995a3`.

Classify as `malicious-package` (typosquat with real remote-code payload).

## Cluster C - npm `chai-as-relay` `pino` impersonator with 4.4MB obfuscated IIFE

`chai-as-relay@1.2.1` (GHSA-mq79-xj84-m775, MAL-2026-17189). Impersonates the legitimate [pino](https://github.com/pinojs/pino) logger project - the README borrows `pino`s keywords, feature bullets, and stated capabilities - while the module`s `index.js` loads a heavily-obfuscated ~4.4 MB blob at module initialisation. The blob is:

- Immediately-Invoked Function Expression (IIFE), so it runs on first evaluation, not on an exported call
- Hex-escaped string arrays
- Control-flow flattening (opaque predicates, chained switch statements)

At 4.4 MB of obfuscated JS the payload is too large for meaningful adversarial static analysis in the general case; treat as opaque hostile code. The module additionally exports a single no-op middleware to keep basic static analysis quiet.

Because the payload fires on `require()`/`import` (not only on `npm install`), a lockfile scan alone is not enough - grep your codebase for `chai-as-relay` in source, tests, and transitively-generated code, and revert any add that was not authored by a known human on your team.

Package author `hello@jsonspack.com`. IOCs: tarball SHA1 `b78835bcec5b368ed0695706aa6eb15ab0c80a1b`, tarball SHA512 SRI `sha512-Gzsi2w4ZEctlgEoQLU5pWM9oD/wKesHwq0uy3SC8wKcvJoLHFcvzvhtAAdQwqueChEII6ZTkaqQYE3XKY2h51Q==`, package.json SHA256 `37af31772ae215ad9ab85f2f37a7c46cbec4bb7b0a10ae13b7b4f19b84778a84`, lib/config.js SHA256 `cc93ac7310b3a044badfc17f112a763bb24452ca88236892a470fdd362a9af36`, source SHA256 `5c65319b0e17f945fc57f482eb174e5d7fe70e63a380cb24f64eea1808bdad2f`. Detected by Amazon Inspector.

Name choice ("chai-as-relay") reads as a chai+chai-as-promised-family test-utility - so the impersonation lure targets developers wiring test tooling, not observability tooling directly. Classify as `malicious-package` (impersonation lure with real payload).

## Cluster D - npm `cma-self-hosted-sandbox-cf` preinstall `/etc/passwd`+`/etc/hosts`+DNS recon to Burp Collaborator OOB

`cma-self-hosted-sandbox-cf@<=1.0.0` (GHSA-wjmh-pc3x-575f, MAL-2026-17190). Preinstall lifecycle hook automatically runs `index.js`, which harvests:

- `os.hostname()` and the user identity block (uid/gid/username/home)
- `/etc/resolv.conf` (DNS resolver configuration)
- `/etc/passwd` (full user/service-account list on the host)
- `/etc/hosts` (any internal-DNS overrides or pinned addresses)

…and POSTs the bundle over HTTPS to `49bl3t5yt786ymbtth24nnlbs2ytmka9.oastify.com`.

`.oastify.com` is a Burp Collaborator out-of-band interaction domain - the same class as `.oast.fun` and `.interactsh.com`. Both authorised pentesters and unauthorised opportunistic actors use it, so the exfil endpoint alone does not tell you which. `/etc/passwd` and `/etc/hosts` are not secrets in themselves, but they reveal service accounts and internal DNS pins that materially help a follow-on stage. The `cma-self-hosted-sandbox-cf` name (`cma` + `self-hosted-sandbox` + `-cf` for Cloudflare) reads as an internal CI sandbox package, so the attempt is directed at an org that runs a private `cma-self-hosted-sandbox-*` scope internally - a dep-confusion probe.

IOCs: index.js SHA256 `fa43f4bd7d96ea8586808a750372d218b48a3a0bf0943f1310cf296b77e52305`, tarball SHA1 `83157fa69aa97b8d23922b3c72d352429c142f10`, tarball SHA512 SRI `sha512-qRbU3aMPgajHHxrME++GmSoMK2L8vXsmvNTve0OHPFOLT9dKoIZoNT22w6Q2W/jAJwG5IgCzGO61AxTzXzkaQg==`.

Classify as `dependency-confusion` (sentinel-name probe with recon payload, no confirmed secret exfil beyond `/etc/passwd`+`/etc/hosts`).

## Operator continuity check

- **`ltidi.storage.googleapis.com`** (yesterday`s Cluster D `@airbnb-extended/typescript-config` GCS-tarball loader): no fresh `@airbnb-extended/*`, `ltidisafe*`, or other GCS-tarball-loader manifests in this window. Egress block remains durable.
- **`oob.algamil7x.xyz`**: no fresh day-9 additions in this window. `.xyz` egress block remains durable on the multi-day pattern.
- **`eo8f3m3ho26a0nm.m.pipedream.net`** (yesterday`s Cluster E `shoplist-app`): no new packages beaconing to this Pipedream endpoint.
- **`simple-date-formatter-new-<N>`** (`124.221.154.135` SSH-beacon family): no `-new-12`/`-16`/higher today. Block remains durable.
- **`n8n-nodes-*` `mkicom.com`**: no new packages. Block remains durable.

Five consecutive-day operators tracked earlier this week all show a one-to-two-day pause in this window - do not remove the blocks on that basis.

## Registry state

All 4 packages in this sweep are npm/pip-quarantined at time of writing. Active operator-side infrastructure unique to today`s batch:

- `thisisafalsepositive.st` + `sltnnt.ru` (Cluster A steganography and secondary)
- Polygon wallet `0x9c0a507300fd902787bb193d80fca5ce6e1bff9a` (Cluster A blockchain C2 lookup)
- `104.234.65.75:700` (Cluster B remote EXE)
- `49bl3t5yt786ymbtth24nnlbs2ytmka9.oastify.com` (Cluster D Burp Collaborator OOB)

## Discovery credits

`GitHub Advisory Database`, `OpenSSF malicious-packages`, `OpenSSF Package Analysis`, `Amazon Inspector`, `kam193/bad-packages`. Per-package IOC details drawn from GHSA and OSSF advisory bodies published between 2026-09-26 12:00 UTC and 2026-09-27 12:00 UTC.

## Impact

- **Cluster A - pip `donutautosellsrc` steganographic loader + Polygon-blockchain C2 + native infostealer (real payload)**: `donutautosellsrc@0.3.7/0.3.8/0.3.9` (GHSA-2w77-qp99-3jvq, MAL-2026-17192, OSSF campaign `2026-09-donutautosellsrc`). Novel-for-this-corpus primitive stack: at install time the package (i) retrieves a remote executable whose payload is embedded in image data using steganography, (ii) drops native (compiled C-extension) Python modules that carry the obfuscated infostealer, and (iii) does not hard-code any C2 hostname - instead it reads command-and-control server addresses from Polygon blockchain transaction history for a specific attacker-controlled wallet, which defeats DNS-based egress denylists because the "C2 address" is fetched from a public blockchain RPC. Observed IOCs: steganography-carrier URL `https://thisisafalsepositive.st/cdn/v2/9f4e7a2c1b8d.png`, secondary domain `sltnnt.ru`, Polygon wallet `0x9c0a507300fd902787bb193d80fca5ce6e1bff9a`. Hashes `d03c42c275f0dbc617428441508c49ae1adcbbc95af4eeb094bca4e4f8943f3e` (payload) and `2ac1203ac68b4bb062c4dd38f59fd8bd13fef695c5b1c8059160c6a5205717b1` (dropper)
- **Cluster B - pip `requests-cache-utils` install-time + import-time remote EXE downloader + browser infostealer (real payload)**: `requests-cache-utils@1.0.0` (GHSA-mc8h-7wqw-2mcf, MAL-2026-17191, OSSF campaign `2026-09-requests-cache-utils`). Overrides `setup.py install` to run at install time, and additionally executes at module import time. Downloads a Windows PE from `http://104.234.65.75:700/setup.exe` and executes it; the remote EXE is a browser-data infostealer per kam193 analysis. Name is a plausible typosquat of the legitimate `requests-cache` and `requests` family - a developer looking for a cache utility for the `requests` library may reach for this by name. Because the install hook runs on `pip install`, no explicit `import` is needed for the payload to fire - a lockfile hit is enough to have downloaded and executed the remote EXE. Hashes `1655ea47fc7ccd39294203776ee3dcb01a394c40d93e05b7b527700b19de42c8` (source), `274c2b93e3c6ca726f21d02f6a8e3602853dbe775a122f5510c42f1d491995a3` (VirusTotal-observed sample)
- **Cluster C - npm `chai-as-relay` `pino` impersonator with 4.4MB obfuscated IIFE loaded at module init (real payload, malicious-package)**: `chai-as-relay@1.2.1` (GHSA-mq79-xj84-m775, MAL-2026-17189). Impersonates the legitimate `pino` logger project (the README, keywords, and stated capabilities crib from `pino`) while the module`s `index.js` loads a heavily-obfuscated ~4.4 MB blob at module initialisation - an IIFE with hex-escaped string arrays and control-flow flattening, no source-mapped provenance. Exports a single no-op middleware to keep static analysis quiet. The payload fires on `require('chai-as-relay')` or `import 'chai-as-relay'` - not just on install - so a project that adds it as a dependency but never runs `npm install` on the affected host is still executing arbitrary code the first time application code touches it. Package author `hello@jsonspack.com`. IOCs: tarball SHA1 `b78835bcec5b368ed0695706aa6eb15ab0c80a1b`, package.json SHA256 `37af31772ae215ad9ab85f2f37a7c46cbec4bb7b0a10ae13b7b4f19b84778a84`, lib/config.js SHA256 `cc93ac7310b3a044badfc17f112a763bb24452ca88236892a470fdd362a9af36`, source SHA256 `5c65319b0e17f945fc57f482eb174e5d7fe70e63a380cb24f64eea1808bdad2f`. Detected by Amazon Inspector
- **Cluster D - npm `cma-self-hosted-sandbox-cf` preinstall Burp-Collaborator recon exfil (real payload, dep-confusion / recon)**: `cma-self-hosted-sandbox-cf@<=1.0.0` (GHSA-wjmh-pc3x-575f, MAL-2026-17190). Preinstall lifecycle hook automatically runs `index.js`, which collects hostname, user identity (uid/gid/username/home), DNS resolver configuration, and the full contents of `/etc/passwd` and `/etc/hosts`, then POSTs the bundle over HTTPS to `49bl3t5yt786ymbtth24nnlbs2ytmka9.oastify.com`. The `.oastify.com` FQDN is a Burp Collaborator out-of-band interaction host - a hallmark of authorised pentest / bug-bounty tooling, though the same infrastructure is also used opportunistically by non-authorised actors. `/etc/passwd` and `/etc/hosts` are not secrets in themselves but reveal user accounts (`_` service accounts and their homes) and internal-DNS overrides (staging hostnames, internal IPs) that materially help follow-on targeting. The `cma-self-hosted-sandbox-cf` name reads as an internal-CI sandbox package (Cloudflare/CMA-flavoured) so treat as a dep-confusion probe against an org that runs a private `cma-self-hosted-sandbox-*` scope internally. Hashes `fa43f4bd7d96ea8586808a750372d218b48a3a0bf0943f1310cf296b77e52305` (index.js), `83157fa69aa97b8d23922b3c72d352429c142f10` (tarball SHA1)
- **Update 2026-09-28 - Cluster A `donutautosellsrc` campaign extends to 4 more pip packages under the same wallet**: `aseity@0.1.0`, `coinscan@0.1.0`, `donutpromotion@<=0.1.0`, `claudedashbord@0.1.0-0.1.3` were quarantined on 2026-09-27 (late) sharing the exact same payload hash `d03c42c275f0dbc617428441508c49ae1adcbbc95af4eeb094bca4e4f8943f3e` and attacker wallet `0x9c0a507300fd902787bb193d80fca5ce6e1bff9a`. See the [2026-09-28 sweep](https://dependencywatch.io/incident/multi-2026-09-28-ghsa-malware-sweep) Cluster A for the extension detail - this is one operator scaling a name catalogue, not four independent copycats
- **Operator continuity check - `ltidi.storage.googleapis.com` day-2 status (Cluster D from yesterday`s sweep)**: no fresh `@airbnb-extended/*`, `ltidisafe*`, or other GCS-tarball-loader manifests appeared in the 2026-09-27 window. The `ltidi.storage.googleapis.com` egress block from yesterday remains the durable mitigation. Similarly no fresh `oob.algamil7x.xyz` day-9 additions, no new `simple-date-formatter-new-<N>` versions, no fresh `n8n-nodes-*` `mkicom.com` variants, no new `124.221.154.135` SSH-beacon packages, and no new `Pipedream` `eo8f3m3ho26a0nm.m.pipedream.net` beacon packages - all five multi-day operators tracked over the last week are quiet in this window. The three network blocks (`ltidi.storage.googleapis.com`, `oob.algamil7x.xyz`, `eo8f3m3ho26a0nm.m.pipedream.net`) remain durable and should NOT be relaxed on a one-to-two-day quiet

## What to do

1. Grep every `package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`, `package.json`, `requirements.txt`, `Pipfile.lock`, `poetry.lock`, and `pyproject.toml` for every package name in Clusters A through D. Uninstall on hit, wipe `node_modules`/`.venv`, delete the lockfile, rebuild against a clean cache. Clusters A, B, and C each contain confirmed real payloads (steganographic + blockchain-C2 infostealer, remote EXE downloader/browser stealer, and a 4.4MB obfuscated on-import loader); a hit on any of those is a compromise, not a warning
2. **For Cluster A (pip `donutautosellsrc` steganographic + Polygon-blockchain C2)**: uninstall on hit and image the host - the native-extension infostealer landed compiled C code on the host, so what a defender sees on disk today may not be the full payload. Rotate every credential the installer user account had access to (browser-saved passwords, wallet extensions, SSH keys, cloud CLI credentials, hardcoded env vars). Because the C2 addresses are fetched from a public Polygon RPC lookup against wallet `0x9c0a507300fd902787bb193d80fca5ce6e1bff9a` rather than a fixed DNS entry, a domain-only egress denylist is not enough - either block the specific IOC domains (`thisisafalsepositive.st`, `sltnnt.ru`, `.st` and `.ru` TLDs if you can tolerate the false-positive rate) OR block outbound Polygon RPC endpoints (`polygon-rpc.com`, `rpc-mainnet.matic.network`, `polygon-mainnet.g.alchemy.com`, `polygon-mainnet.infura.io`, common public RPCs) from build/CI networks. Add a lockfile-lint rule that rejects `donutautosellsrc` outright
3. **For Cluster B (pip `requests-cache-utils` install-time remote EXE)**: uninstall on hit. On any Windows host or Wine-enabled Linux runner that ran `pip install requests-cache-utils`, assume `setup.exe` from `104.234.65.75:700` executed - treat the host as compromised, rotate every browser-saved credential, log out of every browser session, revoke every OAuth grant on your identity providers. Block `104.234.65.75` at network egress. If your team also uses the legitimate `requests-cache` package, add a lockfile-lint rule that explicitly rejects `requests-cache-utils` given the extreme name-collision risk. Adopt `pip install --no-deps` for any install of an unverified package
4. **For Cluster C (npm `chai-as-relay` `pino` impersonator, on-import 4.4MB blob)**: uninstall on hit. Because the payload fires on `require()`/`import` rather than only on install, a lockfile scan alone is not enough - grep your codebase for `chai-as-relay` (in source, in tests, in transitively-generated code) and revert any add that was not authored by a known human on your team. Assume the module ran the first time the affected process started; rotate everything that process had in memory (credentials the app read from env vars, session cookies it held, DB connection strings). The 4.4MB obfuscated IIFE is too large for meaningful adversarial static analysis in the general case; treat as opaque hostile code. Add a lockfile-lint rule that rejects any dependency whose maintainer email is `hello@jsonspack.com`
5. **For Cluster D (npm `cma-self-hosted-sandbox-cf` preinstall recon)**: uninstall on hit. Recon-only in payload (no secret material beyond `/etc/passwd`+`/etc/hosts`+DNS config), but the operator now has a partial map of your host: usernames, service accounts, internal-DNS overrides, and DNS-resolver configuration. Block `49bl3t5yt786ymbtth24nnlbs2ytmka9.oastify.com` at network egress and (if operationally tolerable) block `*.oastify.com` and `*.oast.fun` outright from build/CI networks - both are Burp Collaborator zones that legitimate first-party code has no reason to reach. If your org has an internal `cma-self-hosted-sandbox-*` scope, pin the internal version in `.npmrc` so the public sentinel cannot resolve preferentially
6. For every `npm install` in CI, prefer `--ignore-scripts` and enforce it at the runner level, and for every `pip install`, prefer resolving from a curated internal mirror rather than PyPI directly. Reject npm dependencies whose resolved URL is not `https://registry.npmjs.org/*` or your private registry (this catches yesterday`s `ltidi.storage.googleapis.com` tarball loader and any future GCS/S3 tarball dep). Extend the pin-lists from prior sweeps with `donutautosellsrc`, `requests-cache-utils` (pip), and `chai-as-relay`, `cma-self-hosted-sandbox-cf` (npm). Keep the `ltidi.storage.googleapis.com`, `oob.algamil7x.xyz`, `eo8f3m3ho26a0nm.m.pipedream.net`, `mkicom.com`, `104.21.3.16`, `124.221.154.135`, and `pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun` blocks from prior days in place - the operators are quiet in the 2026-09-27 window but the blocks are durable

## Check your own dependencies

- Check a package-lock.json against this incident: https://dependencywatch.io/check/package-lock-json
- Check a requirements.txt against this incident: https://dependencywatch.io/check/requirements-txt

The scan runs entirely in the browser; lockfile contents are never uploaded.

## References

- [GitHub Advisory Database - recent malware advisories](https://github.com/advisories?query=type%3Amalware&sort=published-desc) - GitHub
- [GHSA-2w77-qp99-3jvq - pip donutautosellsrc (Cluster A - steganography + Polygon-blockchain C2 + native infostealer, MAL-2026-17192)](https://github.com/advisories/GHSA-2w77-qp99-3jvq) - GitHub
- [GHSA-mc8h-7wqw-2mcf - pip requests-cache-utils (Cluster B - setup.py remote-EXE downloader + browser infostealer, MAL-2026-17191)](https://github.com/advisories/GHSA-mc8h-7wqw-2mcf) - GitHub
- [GHSA-mq79-xj84-m775 - npm chai-as-relay (Cluster C - pino impersonator, 4.4MB obfuscated IIFE on import, MAL-2026-17189)](https://github.com/advisories/GHSA-mq79-xj84-m775) - GitHub
- [GHSA-wjmh-pc3x-575f - npm cma-self-hosted-sandbox-cf (Cluster D - preinstall /etc/passwd+/etc/hosts recon to oastify.com OOB, MAL-2026-17190)](https://github.com/advisories/GHSA-wjmh-pc3x-575f) - GitHub
- [OSSF malicious-packages - MAL-2026-17192 donutautosellsrc](https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/donutautosellsrc/MAL-2026-17192.json) - OpenSSF
- [OSSF malicious-packages - MAL-2026-17191 requests-cache-utils](https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/requests-cache-utils/MAL-2026-17191.json) - OpenSSF
- [OSSF malicious-packages - MAL-2026-17189 chai-as-relay](https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-relay/MAL-2026-17189.json) - OpenSSF
- [OSSF malicious-packages - MAL-2026-17190 cma-self-hosted-sandbox-cf](https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cma-self-hosted-sandbox-cf/MAL-2026-17190.json) - OpenSSF

---

Canonical page: https://dependencywatch.io/incident/multi-2026-09-27-ghsa-malware-sweep
Markdown version: https://dependencywatch.io/incident/multi-2026-09-27-ghsa-malware-sweep.md
Site index for agents: https://dependencywatch.io/llms.txt
DependencyWatch.io is operated by Precursor Security (https://precursorsecurity.com).
