Feed
HighPublished 16 Jul 202618 packages · 154 versions

GitHub Advisory malware sweep — 18 npm packages (2 Claude / Anthropic-brand typosquats, 3-package `chain-sdk-js` / `theta-sdk-js` / `ai-pro-sdk` mid-July SDK cluster, 3-package `ai-p2p` / `websight-p2p` / `websight2-p2p` June 15 P2P burst, 3 auto-publisher sleepers `px8my` (55 versions) / `monogrok` (21 versions) / `scan-only` (16 versions), plus WordPress Gutenberg / terminal-toy / singleton fillers) retired 2026-07-16 → 2026-07-17

Summary

On 2026-07-16 and 2026-07-17 GitHub's Advisory Database retired 18 CWE-506 npm malware advisories (separate from 2 additional chai-as-* retirements folded into the existing jsonspack DPRK incident). Highlights: anthropic-claude-latest — a version-matched (4.7.1 / 4.7.2 / 4.7.3) typosquat of Anthropic's Claude Code CLI — and claude-token-tracker-mcp, an MCP-shape package targeting Claude Code's OAuth-token traffic (matching the Mitiga Labs "MCP token theft" attack chain that abuses .claude.json).

typosquatdependency-confusiondormant-domaincredential-theftobfuscation
Detected by
GitHub Advisory Database · npm Security · Mitiga Labs (attack-chain context)
Also known as
2026-07-16 GHSA npm sweep · anthropic-claude-latest Claude typosquat pair · chain-sdk-js mid-July SDK cluster · websight-p2p June 15 P2P burst
Ecosystems
npm
Packages tracked
18

What happened

On 2026-07-16 and 2026-07-17 GitHub's Advisory Database published 20 CWE-506 (Embedded Malicious Code) advisories against npm packages. Two of them (chai-as-const and chai-as-thread) are the July continuation of the jsonspack DPRK campaign already catalogued in the June 2026 incident; the remaining 18 are captured here, grouped by publisher signature. Every record uses the standard "any computer that has this package installed or running should be considered fully compromised — rotate all secrets from a different computer" boilerplate.

Cluster 1 — Claude / Anthropic-brand typosquat pair (2 packages)

| Package | Versions | Publish (UTC) | GHSA replacement (UTC) | |---|---|---|---| | anthropic-claude-latest | 4.7.1, 4.7.2, 4.7.3 | 2026-06-20 11:50:16 → 12:31:01 | 2026-07-17 05:38:22 | | claude-token-tracker-mcp | 1.0.0 | 2026-06-16 12:53:21 | 2026-07-16 06:50:13 |

anthropic-claude-latest

The version pin 4.7.x matches Anthropic's current Claude Opus 4.7 marketing name exactly — a developer trying to install a Claude-branded npm helper by memory (rather than reaching for the canonical @anthropic-ai/claude-code scope) hits this typosquat first. The three patch bumps 4.7.14.7.3 inside 41 minutes match the version-race pattern seen on other AI-tooling typosquats (ai-pro-sdk below, openai-agents-helpers on the 2026-07-07 sweep).

claude-token-tracker-mcp and the Mitiga Labs MCP token-theft attack chain

The claude-token-tracker-mcp slug directly maps to Mitiga Labs' June 2026 attack-chain disclosure: a malicious npm package containing a hidden postinstall hook that rewrites ~/.claude.json (Claude Code's global MCP configuration) to route all MCP traffic through an attacker-controlled localhost proxy. The proxy intercepts long-lived OAuth bearer tokens the developer has granted for connected SaaS platforms — Jira, Confluence, GitHub, and every other MCP server — while remaining indistinguishable from legitimate traffic on the provider side. Mitiga reported the attack chain to Anthropic on 2026-04-10; Anthropic ruled the report out of scope on 2026-04-12, citing user consent for the initial package install. No client-side patch has shipped, so the mitigation for any host that resolved claude-token-tracker-mcp is: audit ~/.claude.json for unexpected mcpServers.*.url entries pointing at localhost:* or 127.0.0.1:*, rotate every OAuth token the Claude Code session had granted, and reimage the affected workstation.

Cluster 2 — Mid-July SDK-typosquat cluster (3 packages)

| Package | Versions | Publish (UTC) | GHSA replacement (UTC) | |---|---|---|---| | chain-sdk-js | 1.0.21.0.6 | 2026-07-14 15:14:07 → 2026-07-15 21:30:58 | 2026-07-16 23:33:18 | | theta-sdk-js | 1.2.141.2.17 | 2026-07-10 12:57:39 → 16:37:43 | 2026-07-16 23:55:37 | | ai-pro-sdk | 2.0.12.0.4 | 2026-07-14 07:19:26 → 2026-07-16 07:39:46 | 2026-07-16 23:29:34 |

Three SDK-suffix names, each with 4-5 rapid patch bumps, retired inside a ~26-minute npm-Security take-down window on 2026-07-16 23:29 → 23:55 UTC. chain-sdk-js targets Chainlink / generic crypto chain-SDK developers; theta-sdk-js maps to the Theta Network blockchain SDK; ai-pro-sdk is a broader AI-SDK typosquat continuing the openai-agents-helpers / anthropic-toolkit / ai-sdk-helpers cluster Socket flagged on 2026-07-07. The 2.0.4 version of ai-pro-sdk was published at 2026-07-16 07:39 UTC — only 16 hours before its own take-down, so the operator was still actively pushing new versions when npm Security caught up.

Cluster 3 — June 15 P2P burst (3 packages)

| Package | Versions | Publish (UTC) | GHSA replacement (UTC) | |---|---|---|---| | websight-p2p | 1.0.01.0.6 | 2026-06-14 17:35:54 → 17:59:22 | 2026-07-16 08:12:20 | | websight2-p2p | 1.0.01.0.4 | 2026-06-15 18:58:24 → 19:09:58 | 2026-07-16 08:12:10 | | ai-p2p | 1.0.01.0.4 | 2026-06-15 19:22:54 → 19:44:34 | 2026-07-16 08:11:52 |

All three packages fit the same fingerprint: 5-7 rapid patch bumps within a ~23-minute publish window, dormant for ~31 days, then retired in a 28-second npm-Security take-down burst on 2026-07-16 08:11:52 → 08:12:20 UTC. Shared version pattern + same-day publication + same-burst retirement = single operator broadening the dep-confusion catchment across three P2P/WebRTC-shaped internal-project slugs.

Cluster 4 — Auto-publisher sleepers (3 packages, ~92 versions combined)

| Package | Version count | Publish window (UTC) | GHSA replacement (UTC) | |---|---|---|---| | px8my | 55 versions 1.0.01.0.54 | 2026-06-18 10:08 → 2026-07-16 12:50 (daily cadence, ~30 days) | 2026-07-16 23:37:43 | | monogrok | 21 versions 1.0.11.0.44 | 2026-06-10 08:00 → 2026-07-16 22:08 | 2026-07-16 23:08:04 | | scan-only | 16 versions 0.2.01.0.0 | 2026-06-17 12:27 → 18:24 (~2-hour burst) | 2026-07-17 05:38:27 |

px8my's 30-day daily-cadence version history (roughly one new patch every 6-12 hours from 2026-06-18 through 2026-07-16) is unusual for a dep-confusion typosquat. Two interpretations fit: (a) a compromised legitimate maintainer account whose auto-publish pipeline was hijacked, with malicious code injected only in the last few versions before retirement; (b) an attacker-run test harness that got weaponized during the window. Either way, all 55 versions should be treated as suspect in any lockfile hit — GHSA's "all versions" affected range makes no distinction.

monogrok's 21-version cadence spans a slower ~5 week window and includes a large gap between 1.0.11 (2026-06-23) and 1.0.14 (2026-07-06), then rapid bumps in the final week — matching the "dormant then late-stage weaponization" tactic seen on the 2026-07-13 getd-* Spanish-enterprise sweep.

scan-only's 16-version burst inside a 2-hour window on 2026-06-17 is the fingerprint of a dep-confusion race — the operator was iterating rapidly to nail the exact semver that would beat a specific internal package. The name aligns with a "scan-only mode" security-tool feature slug that has been publicly discussed as a Nessus / Nmap / Semgrep configuration flag.

Cluster 5 — WordPress Gutenberg / terminal-toy fillers (4 packages)

| Package | Versions | Publish (UTC) | GHSA replacement (UTC) | |---|---|---|---| | my-tailwind-gutenberg-block | 0.1.00.1.5 | 2026-07-16 16:31:22 → 21:00:42 | 2026-07-16 22:27:57 | | awesome-terminal | 1.0.11.0.4 | 2026-07-11 08:29:06 → 2026-07-15 17:47:47 | 2026-07-16 23:31:42 | | terminal-mascot | 1.0.03.5.3 | 2026-07-11 06:20:50 → 2026-07-15 17:52:05 | 2026-07-16 23:54:46 | | wordpad-text-ui | 1.0.01.0.2 | 2026-06-16 02:35:29 → 02:43:26 | 2026-07-16 08:09:22 |

my-tailwind-gutenberg-block is the only package in this sweep to be published and retired the same day (2026-07-16) — 90 minutes between the final version push (21:00 UTC) and the GHSA replacement (22:27 UTC). The exposure window is narrow but the target is a WordPress Gutenberg block-editor build chain with elevated npm-install privileges on a plugin-developer's machine.

awesome-terminal and terminal-mascot were both published within the same 30-minute window on 2026-07-11 08:00 → 08:47 UTC — same-hour publish coordination points to a single operator. terminal-mascot also shows the classic version-race fingerprint: a jump from 1.0.3 to 3.5.2 inside 30 minutes to guarantee semver resolution beats any legitimate internal package.

Cluster 6 — Singletons (3 packages)

| Package | Versions | Publish (UTC) | GHSA replacement (UTC) | |---|---|---|---| | hehehe | 1.0.01.0.7 + 2.0.1, 2.0.2 | 2026-05-05 16:30 → 2026-07-15 20:34 | 2026-07-16 23:36:30 | | vor8zakon | 1.0.0 | 2026-06-15 14:36:51 | 2026-07-16 07:27:42 | | loader1 | 2.1.22.1.7 | 2026-06-15 20:13:02 → 21:25:13 | 2026-07-16 08:12:03 |

hehehe is the odd one — an initial burst of 1.0.0..1.0.7 in May was likely benign / abandoned, then two 2.0.x republishes on 2026-07-15 (12:04 → 20:34 UTC) triggered the retirement. Any host that resolved 2.0.1 or 2.0.2 is the actual exposure. vor8zakon's slug (vor = "thief" in Russian, zakon = "law" — colloquially "the criminal code") is unusual and may point to a specific Russian-language internal target. loader1 fits the generic-name dep-confusion pattern that has caught up seven bundler-tool typosquats already this month.

Cross-cluster notes

  • The 72 aggregate versions across 18 packages compare to 145 versions across 25 packages on the 2026-07-15 sweep and roughly 60 versions across 14 packages on the 2026-07-13 sweep.
  • The anthropic-claude-latest + claude-token-tracker-mcp pair is the first clear Claude / Anthropic brand-targeting we've seen in a GHSA sweep. Previous Claude-related supply-chain incidents (mouse5212-claude-ai-exfil, mouse5212-super-formatter) targeted Claude artifact directories, not the Anthropic brand namespace. Expect more @anthropic-ai/* and claude-* typosquats now that the pattern has proven successful.
  • The July 16 retirements land while Anthropic's own Claude Code CLI is under review for a separate steganographic-tracker controversy — coincidence, but the two stories together mean any Claude-related npm search returns has to be triaged carefully.

Registry state

Every package now resolves to a 0.0.1-security holding tarball owned by npm Security. Historical version tarballs may remain fetchable from the CDN for 24-72 hours after the security replacement lands and should be treated as live malware in any lockfile hit — regardless of exact version. Because the security replacement wipes the historical version list from the public registry response, the versions map below records the concrete versions observed pre-replacement via npm registry time-object inspection.

Affected packages (18)

  • npmai-p2p
    1.0.01.0.11.0.21.0.31.0.4
  • npmai-pro-sdk
    2.0.12.0.22.0.32.0.4
  • npmanthropic-claude-latest
    4.7.14.7.24.7.3
  • npmawesome-terminal
    1.0.11.0.21.0.31.0.4
  • npmchain-sdk-js
    1.0.21.0.31.0.41.0.51.0.6
  • npmclaude-token-tracker-mcp
    1.0.0
  • npmhehehe
    1.0.01.0.41.0.51.0.61.0.72.0.12.0.2
  • npmloader1
    2.1.22.1.32.1.42.1.52.1.62.1.7
  • npmmonogrok
    1.0.11.0.71.0.81.0.111.0.141.0.301.0.311.0.321.0.331.0.341.0.351.0.361.0.371.0.391.0.401.0.411.0.431.0.44
  • npmmy-tailwind-gutenberg-block
    0.1.00.1.20.1.30.1.40.1.5
  • npmpx8my
    1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.201.0.211.0.221.0.231.0.241.0.251.0.261.0.271.0.281.0.291.0.301.0.311.0.321.0.331.0.341.0.351.0.361.0.371.0.381.0.391.0.401.0.411.0.421.0.431.0.441.0.451.0.461.0.471.0.481.0.491.0.501.0.511.0.521.0.531.0.54
  • npmscan-only
    0.2.00.3.00.4.00.4.10.4.20.4.30.4.40.4.50.4.60.4.70.4.80.4.90.5.00.5.11.0.0
  • npmterminal-mascot
    1.0.01.0.11.0.21.0.33.5.23.5.3
  • npmtheta-sdk-js
    1.2.141.2.151.2.161.2.17
  • npmvor8zakon
    1.0.0
  • npmwebsight-p2p
    1.0.01.0.11.0.21.0.31.0.41.0.51.0.6
  • npmwebsight2-p2p
    1.0.01.0.11.0.21.0.31.0.4
  • npmwordpad-text-ui
    1.0.01.0.11.0.2

Impact

  • Any host that installed any of the 18 packages listed below should be treated as fully compromised — every GHSA record uses the boilerplate CWE-506 "rotate all secrets from a different computer" language, and no patched version exists for any of them
  • Claude / Anthropic-brand typosquat pair (2 packages): anthropic-claude-latest@4.7.1,4.7.2,4.7.3 (published 2026-06-20 11:50 → 12:31 UTC) and claude-token-tracker-mcp@1.0.0 (published 2026-06-16 12:53 UTC, retired 2026-07-16 06:50 UTC). The 4.7.x version pin on anthropic-claude-latest is a deliberate lock to the current Claude Opus 4.7 marketing version — any developer trying to install a Claude-branded npm helper by memory (rather than the canonical @anthropic-ai/claude-code, @anthropic-ai/sdk, or @anthropic-ai/tokenizer) is the target. The claude-token-tracker-mcp name aligns with the Mitiga Labs MCP token-theft attack chain in which a malicious npm package rewrites ~/.claude.json on install to route Claude Code MCP traffic through an attacker localhost proxy, harvesting long-lived OAuth bearer tokens for every SaaS platform (Jira / Confluence / GitHub) the developer had connected. Anthropic told Mitiga the attack chain is out of scope pending user consent — no client-side patch will be shipped
  • Mid-July SDK-typosquat cluster (3 packages): chain-sdk-js@1.0.2..1.0.6 (2026-07-14 15:14 → 2026-07-15 21:30 UTC), theta-sdk-js@1.2.14..1.2.17 (2026-07-10 12:57 → 16:37 UTC), ai-pro-sdk@2.0.1..2.0.4 (2026-07-14 07:19 → 2026-07-16 07:39 UTC). All three share the same shape: SDK-suffix name, 3-6 rapid patch bumps in a single day, retired within 8 hours in the same npm-Security burst on 2026-07-16 23:29 → 23:55 UTC. The chain-sdk-js slug likely targets Chainlink / crypto chain-SDK developers; theta-sdk-js maps to the Theta Network blockchain SDK; ai-pro-sdk is a broader AI-SDK typosquat continuing the openai-agents-helpers / anthropic-toolkit / ai-sdk-helpers cluster Socket flagged on 2026-07-07
  • June 15 P2P burst (3 packages): ai-p2p@1.0.0..1.0.4, websight-p2p@1.0.0..1.0.6, websight2-p2p@1.0.0..1.0.4 — all published within a 72-minute window on 2026-06-14 17:35 → 2026-06-15 19:44 UTC, retired in a 28-second npm-Security take-down burst on 2026-07-16 08:11:52 → 08:12:20 UTC. Shared version-numbering pattern (1.0.01.0.4/1.0.6 rapid patch bumps within minutes of first publish), same day publication, same retirement burst — one operator broadening the dep-confusion catchment across three P2P/WebRTC-shaped internal-project slugs
  • Auto-publisher sleepers with mass version histories (3 packages): px8my (55 versions across 1.0.0 → 1.0.54 — a daily-cadence auto-publisher running 2026-06-18 → 2026-07-16, roughly 30 days of scheduled npm publish calls at similar times of day), monogrok (21 versions 1.0.1 → 1.0.44 across 2026-06-10 → 2026-07-16), scan-only (16 versions 0.2.0 → 1.0.0 in a ~2-hour burst on 2026-06-17 12:27 → 18:24 UTC). px8my's 30-day version cadence is unusual for a dep-confusion typosquat — it fits either (a) a compromised legitimate maintainer account with an auto-publish pipeline, or (b) an attacker-run test harness that got weaponized in the last few versions. scan-only is likely a security-tool internal name (aligns with a "scan-only mode" static-analyzer feature slug) that got typosquatted for a specific internal target
  • WordPress Gutenberg / terminal-toy fillers (4 packages): my-tailwind-gutenberg-block@0.1.0..0.1.5 (2026-07-16 same-day burst 16:31 → 21:00 UTC — the only package retired within hours of its first publish), awesome-terminal@1.0.1..1.0.4 + terminal-mascot@1.0.0..3.5.3 (both published 2026-07-11 08:00 → 08:47 UTC and retired 2026-07-16 23:31 → 23:54 UTC — same-hour publish coordination), wordpad-text-ui@1.0.0..1.0.2 (2026-06-16 02:35 → 02:43 UTC). The terminal-mascot version jump from 1.0.3 to 3.5.2 inside 30 minutes is the fingerprint of a version-race dep-confusion pin
  • Singletons (3 packages): hehehe@1.0.0..2.0.2 (an odd 2-generation package with 1.0.x versions from 2026-05-05 → 2026-05-20 and 2.0.1/2.0.2 republished 2026-07-15 12:04 → 20:34 UTC — the 2.0.x payload is what triggered retirement), vor8zakon@1.0.0 (single version 2026-06-15 14:36 UTC, retired 2026-07-16 07:27 UTC — likely a Russian-language internal slug, vor = "thief" / "zakon" = "law"), loader1@2.1.2..2.1.7 (2026-06-15 20:13 → 21:25 UTC 6-version burst)
  • No payload write-up accompanies the GHSA texts for any of these 18 packages — defenders should treat install-time behavior as unanalyzed and assume worst case for any host that resolved these names

What to do

  1. 1Grep every lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml) for each name in the packages map below. Any match is a supply-chain incident: rotate every credential the build runner could reach and re-image the build host
  2. 2If your project imports anthropic-claude-latest or claude-token-tracker-mcp: replace with the canonical Anthropic-published packages — @anthropic-ai/claude-code, @anthropic-ai/sdk, @anthropic-ai/tokenizer, @anthropic-ai/bedrock-sdk, or @anthropic-ai/vertex-sdk. Always verify the @anthropic-ai/ scope prefix. For claude-token-tracker-mcp specifically: audit ~/.claude.json on every developer workstation for unexpected MCP server URLs pointing at localhost:* proxies (per the Mitiga Labs attack chain — the malicious postinstall hook rewrites the file to route MCP traffic through an attacker-controlled localhost proxy). Rotate every OAuth token the Claude Code session had access to: GitHub, Jira, Confluence, and any other SaaS-connected MCP server
  3. 3If you had chain-sdk-js, theta-sdk-js, or ai-pro-sdk in a lockfile: these are typosquats of well-known ecosystem SDKs. Use the canonical @chainlink/contracts, @theta-labs/theta-js, or the ai (@vercel/ai-sdk) / openai / @anthropic-ai/sdk packages depending on which real SDK you actually needed. Remove the malicious dependencies and rotate any credentials the CI environment could reach — build-time postinstall hooks reach cloud metadata, secrets stores, and any environment variables loaded by the runner
  4. 4If you had ai-p2p, websight-p2p, or websight2-p2p in a lockfile: none of these have a legitimate first-party parent on npm. These are internal-project dep-confusion pins. Register the -p2p-suffix namespaces as defensive stubs on the public registry (npm publish an empty @yourorg/p2p-* package) and pin the internal registry as the primary source via .npmrc scope-registry routing
  5. 5If you had px8my, monogrok, or scan-only in a lockfile: audit the 55/21/16 concrete versions individually (see packages map below). px8my's 30-day auto-publish cadence means many teams pulled it into an automated dependency-refresh PR at some point during the window. scan-only in particular is likely to be a security-tool internal name — check whether your organization has an internal scan-only package on a private registry that this attacker was trying to dep-confuse
  6. 6If you had any of the terminal-toy / WordPress / singleton fillers (awesome-terminal, terminal-mascot, wordpad-text-ui, my-tailwind-gutenberg-block, hehehe, vor8zakon, loader1): none have legitimate first-party parents. Remove; treat as a supply-chain incident. For my-tailwind-gutenberg-block specifically: audit any WordPress Gutenberg build pipeline that resolved this dependency — it was published and retired the same day, so the exposure window is narrow but the target is a WordPress plugin build chain with elevated CI access
  7. 7Verify none of the 18 listed packages still resolves via your private mirror — internal Artifactory / Nexus / Verdaccio instances routinely cache tarballs and will keep serving the malicious versions after the public yank
  8. 8For projects using postinstall-scripting packages, consider running npm install --ignore-scripts in CI as a defense-in-depth measure and re-invoking scripts only for vetted first-party packages (the upcoming npm v12 defaults do this, per the npm v12 announcement)

References

npm-2026-07-16-ghsa-malware-sweep