GitHub Advisory malware sweep — 18 npm packages (2 Claude / Anthropic-brand typosquats, 3-package `chain-sdk-js` / `theta-sdk-js` / `ai-pro-sdk` mid-July SDK cluster, 3-package `ai-p2p` / `websight-p2p` / `websight2-p2p` June 15 P2P burst, 3 auto-publisher sleepers `px8my` (55 versions) / `monogrok` (21 versions) / `scan-only` (16 versions), plus WordPress Gutenberg / terminal-toy / singleton fillers) retired 2026-07-16 → 2026-07-17
On 2026-07-16 and 2026-07-17 GitHub's Advisory Database retired 18 CWE-506 npm malware advisories (separate from 2 additional chai-as-* retirements folded into the existing jsonspack DPRK incident). Highlights: anthropic-claude-latest — a version-matched (4.7.1 / 4.7.2 / 4.7.3) typosquat of Anthropic's Claude Code CLI — and claude-token-tracker-mcp, an MCP-shape package targeting Claude Code's OAuth-token traffic (matching the Mitiga Labs "MCP token theft" attack chain that abuses .claude.json).
- Detected by
- GitHub Advisory Database · npm Security · Mitiga Labs (attack-chain context)
- Also known as
- 2026-07-16 GHSA npm sweep · anthropic-claude-latest Claude typosquat pair · chain-sdk-js mid-July SDK cluster · websight-p2p June 15 P2P burst
- Ecosystems
- npm
- Packages tracked
- 18
What happened
On 2026-07-16 and 2026-07-17 GitHub's Advisory Database published 20 CWE-506 (Embedded Malicious Code) advisories against npm packages. Two of them (chai-as-const and chai-as-thread) are the July continuation of the jsonspack DPRK campaign already catalogued in the June 2026 incident; the remaining 18 are captured here, grouped by publisher signature. Every record uses the standard "any computer that has this package installed or running should be considered fully compromised — rotate all secrets from a different computer" boilerplate.
Cluster 1 — Claude / Anthropic-brand typosquat pair (2 packages)
| Package | Versions | Publish (UTC) | GHSA replacement (UTC) | |---|---|---|---| | anthropic-claude-latest | 4.7.1, 4.7.2, 4.7.3 | 2026-06-20 11:50:16 → 12:31:01 | 2026-07-17 05:38:22 | | claude-token-tracker-mcp | 1.0.0 | 2026-06-16 12:53:21 | 2026-07-16 06:50:13 |
anthropic-claude-latest
The version pin 4.7.x matches Anthropic's current Claude Opus 4.7 marketing name exactly — a developer trying to install a Claude-branded npm helper by memory (rather than reaching for the canonical @anthropic-ai/claude-code scope) hits this typosquat first. The three patch bumps 4.7.1 → 4.7.3 inside 41 minutes match the version-race pattern seen on other AI-tooling typosquats (ai-pro-sdk below, openai-agents-helpers on the 2026-07-07 sweep).
claude-token-tracker-mcp and the Mitiga Labs MCP token-theft attack chain
The claude-token-tracker-mcp slug directly maps to Mitiga Labs' June 2026 attack-chain disclosure: a malicious npm package containing a hidden postinstall hook that rewrites ~/.claude.json (Claude Code's global MCP configuration) to route all MCP traffic through an attacker-controlled localhost proxy. The proxy intercepts long-lived OAuth bearer tokens the developer has granted for connected SaaS platforms — Jira, Confluence, GitHub, and every other MCP server — while remaining indistinguishable from legitimate traffic on the provider side. Mitiga reported the attack chain to Anthropic on 2026-04-10; Anthropic ruled the report out of scope on 2026-04-12, citing user consent for the initial package install. No client-side patch has shipped, so the mitigation for any host that resolved claude-token-tracker-mcp is: audit ~/.claude.json for unexpected mcpServers.*.url entries pointing at localhost:* or 127.0.0.1:*, rotate every OAuth token the Claude Code session had granted, and reimage the affected workstation.
Cluster 2 — Mid-July SDK-typosquat cluster (3 packages)
| Package | Versions | Publish (UTC) | GHSA replacement (UTC) | |---|---|---|---| | chain-sdk-js | 1.0.2 → 1.0.6 | 2026-07-14 15:14:07 → 2026-07-15 21:30:58 | 2026-07-16 23:33:18 | | theta-sdk-js | 1.2.14 → 1.2.17 | 2026-07-10 12:57:39 → 16:37:43 | 2026-07-16 23:55:37 | | ai-pro-sdk | 2.0.1 → 2.0.4 | 2026-07-14 07:19:26 → 2026-07-16 07:39:46 | 2026-07-16 23:29:34 |
Three SDK-suffix names, each with 4-5 rapid patch bumps, retired inside a ~26-minute npm-Security take-down window on 2026-07-16 23:29 → 23:55 UTC. chain-sdk-js targets Chainlink / generic crypto chain-SDK developers; theta-sdk-js maps to the Theta Network blockchain SDK; ai-pro-sdk is a broader AI-SDK typosquat continuing the openai-agents-helpers / anthropic-toolkit / ai-sdk-helpers cluster Socket flagged on 2026-07-07. The 2.0.4 version of ai-pro-sdk was published at 2026-07-16 07:39 UTC — only 16 hours before its own take-down, so the operator was still actively pushing new versions when npm Security caught up.
Cluster 3 — June 15 P2P burst (3 packages)
| Package | Versions | Publish (UTC) | GHSA replacement (UTC) | |---|---|---|---| | websight-p2p | 1.0.0 → 1.0.6 | 2026-06-14 17:35:54 → 17:59:22 | 2026-07-16 08:12:20 | | websight2-p2p | 1.0.0 → 1.0.4 | 2026-06-15 18:58:24 → 19:09:58 | 2026-07-16 08:12:10 | | ai-p2p | 1.0.0 → 1.0.4 | 2026-06-15 19:22:54 → 19:44:34 | 2026-07-16 08:11:52 |
All three packages fit the same fingerprint: 5-7 rapid patch bumps within a ~23-minute publish window, dormant for ~31 days, then retired in a 28-second npm-Security take-down burst on 2026-07-16 08:11:52 → 08:12:20 UTC. Shared version pattern + same-day publication + same-burst retirement = single operator broadening the dep-confusion catchment across three P2P/WebRTC-shaped internal-project slugs.
Cluster 4 — Auto-publisher sleepers (3 packages, ~92 versions combined)
| Package | Version count | Publish window (UTC) | GHSA replacement (UTC) | |---|---|---|---| | px8my | 55 versions 1.0.0 → 1.0.54 | 2026-06-18 10:08 → 2026-07-16 12:50 (daily cadence, ~30 days) | 2026-07-16 23:37:43 | | monogrok | 21 versions 1.0.1 → 1.0.44 | 2026-06-10 08:00 → 2026-07-16 22:08 | 2026-07-16 23:08:04 | | scan-only | 16 versions 0.2.0 → 1.0.0 | 2026-06-17 12:27 → 18:24 (~2-hour burst) | 2026-07-17 05:38:27 |
px8my's 30-day daily-cadence version history (roughly one new patch every 6-12 hours from 2026-06-18 through 2026-07-16) is unusual for a dep-confusion typosquat. Two interpretations fit: (a) a compromised legitimate maintainer account whose auto-publish pipeline was hijacked, with malicious code injected only in the last few versions before retirement; (b) an attacker-run test harness that got weaponized during the window. Either way, all 55 versions should be treated as suspect in any lockfile hit — GHSA's "all versions" affected range makes no distinction.
monogrok's 21-version cadence spans a slower ~5 week window and includes a large gap between 1.0.11 (2026-06-23) and 1.0.14 (2026-07-06), then rapid bumps in the final week — matching the "dormant then late-stage weaponization" tactic seen on the 2026-07-13 getd-* Spanish-enterprise sweep.
scan-only's 16-version burst inside a 2-hour window on 2026-06-17 is the fingerprint of a dep-confusion race — the operator was iterating rapidly to nail the exact semver that would beat a specific internal package. The name aligns with a "scan-only mode" security-tool feature slug that has been publicly discussed as a Nessus / Nmap / Semgrep configuration flag.
Cluster 5 — WordPress Gutenberg / terminal-toy fillers (4 packages)
| Package | Versions | Publish (UTC) | GHSA replacement (UTC) | |---|---|---|---| | my-tailwind-gutenberg-block | 0.1.0 → 0.1.5 | 2026-07-16 16:31:22 → 21:00:42 | 2026-07-16 22:27:57 | | awesome-terminal | 1.0.1 → 1.0.4 | 2026-07-11 08:29:06 → 2026-07-15 17:47:47 | 2026-07-16 23:31:42 | | terminal-mascot | 1.0.0 → 3.5.3 | 2026-07-11 06:20:50 → 2026-07-15 17:52:05 | 2026-07-16 23:54:46 | | wordpad-text-ui | 1.0.0 → 1.0.2 | 2026-06-16 02:35:29 → 02:43:26 | 2026-07-16 08:09:22 |
my-tailwind-gutenberg-block is the only package in this sweep to be published and retired the same day (2026-07-16) — 90 minutes between the final version push (21:00 UTC) and the GHSA replacement (22:27 UTC). The exposure window is narrow but the target is a WordPress Gutenberg block-editor build chain with elevated npm-install privileges on a plugin-developer's machine.
awesome-terminal and terminal-mascot were both published within the same 30-minute window on 2026-07-11 08:00 → 08:47 UTC — same-hour publish coordination points to a single operator. terminal-mascot also shows the classic version-race fingerprint: a jump from 1.0.3 to 3.5.2 inside 30 minutes to guarantee semver resolution beats any legitimate internal package.
Cluster 6 — Singletons (3 packages)
| Package | Versions | Publish (UTC) | GHSA replacement (UTC) | |---|---|---|---| | hehehe | 1.0.0–1.0.7 + 2.0.1, 2.0.2 | 2026-05-05 16:30 → 2026-07-15 20:34 | 2026-07-16 23:36:30 | | vor8zakon | 1.0.0 | 2026-06-15 14:36:51 | 2026-07-16 07:27:42 | | loader1 | 2.1.2 → 2.1.7 | 2026-06-15 20:13:02 → 21:25:13 | 2026-07-16 08:12:03 |
hehehe is the odd one — an initial burst of 1.0.0..1.0.7 in May was likely benign / abandoned, then two 2.0.x republishes on 2026-07-15 (12:04 → 20:34 UTC) triggered the retirement. Any host that resolved 2.0.1 or 2.0.2 is the actual exposure. vor8zakon's slug (vor = "thief" in Russian, zakon = "law" — colloquially "the criminal code") is unusual and may point to a specific Russian-language internal target. loader1 fits the generic-name dep-confusion pattern that has caught up seven bundler-tool typosquats already this month.
Cross-cluster notes
- The 72 aggregate versions across 18 packages compare to 145 versions across 25 packages on the 2026-07-15 sweep and roughly 60 versions across 14 packages on the 2026-07-13 sweep.
- The
anthropic-claude-latest+claude-token-tracker-mcppair is the first clear Claude / Anthropic brand-targeting we've seen in a GHSA sweep. Previous Claude-related supply-chain incidents (mouse5212-claude-ai-exfil,mouse5212-super-formatter) targeted Claude artifact directories, not the Anthropic brand namespace. Expect more@anthropic-ai/*andclaude-*typosquats now that the pattern has proven successful. - The July 16 retirements land while Anthropic's own Claude Code CLI is under review for a separate steganographic-tracker controversy — coincidence, but the two stories together mean any Claude-related npm search returns has to be triaged carefully.
Registry state
Every package now resolves to a 0.0.1-security holding tarball owned by npm Security. Historical version tarballs may remain fetchable from the CDN for 24-72 hours after the security replacement lands and should be treated as live malware in any lockfile hit — regardless of exact version. Because the security replacement wipes the historical version list from the public registry response, the versions map below records the concrete versions observed pre-replacement via npm registry time-object inspection.
Affected packages (18)
- npm
ai-p2p1.0.01.0.11.0.21.0.31.0.4 - npm
ai-pro-sdk2.0.12.0.22.0.32.0.4 - npm
anthropic-claude-latest4.7.14.7.24.7.3 - npm
awesome-terminal1.0.11.0.21.0.31.0.4 - npm
chain-sdk-js1.0.21.0.31.0.41.0.51.0.6 - npm
claude-token-tracker-mcp1.0.0 - npm
hehehe1.0.01.0.41.0.51.0.61.0.72.0.12.0.2 - npm
loader12.1.22.1.32.1.42.1.52.1.62.1.7 - npm
monogrok1.0.11.0.71.0.81.0.111.0.141.0.301.0.311.0.321.0.331.0.341.0.351.0.361.0.371.0.391.0.401.0.411.0.431.0.44 - npm
my-tailwind-gutenberg-block0.1.00.1.20.1.30.1.40.1.5 - npm
px8my1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.201.0.211.0.221.0.231.0.241.0.251.0.261.0.271.0.281.0.291.0.301.0.311.0.321.0.331.0.341.0.351.0.361.0.371.0.381.0.391.0.401.0.411.0.421.0.431.0.441.0.451.0.461.0.471.0.481.0.491.0.501.0.511.0.521.0.531.0.54 - npm
scan-only0.2.00.3.00.4.00.4.10.4.20.4.30.4.40.4.50.4.60.4.70.4.80.4.90.5.00.5.11.0.0 - npm
terminal-mascot1.0.01.0.11.0.21.0.33.5.23.5.3 - npm
theta-sdk-js1.2.141.2.151.2.161.2.17 - npm
vor8zakon1.0.0 - npm
websight-p2p1.0.01.0.11.0.21.0.31.0.41.0.51.0.6 - npm
websight2-p2p1.0.01.0.11.0.21.0.31.0.4 - npm
wordpad-text-ui1.0.01.0.11.0.2
Impact
- Any host that installed any of the 18 packages listed below should be treated as fully compromised — every GHSA record uses the boilerplate CWE-506 "rotate all secrets from a different computer" language, and no patched version exists for any of them
- Claude / Anthropic-brand typosquat pair (2 packages):
anthropic-claude-latest@4.7.1,4.7.2,4.7.3(published 2026-06-20 11:50 → 12:31 UTC) andclaude-token-tracker-mcp@1.0.0(published 2026-06-16 12:53 UTC, retired 2026-07-16 06:50 UTC). The4.7.xversion pin onanthropic-claude-latestis a deliberate lock to the current Claude Opus 4.7 marketing version — any developer trying to install a Claude-branded npm helper by memory (rather than the canonical@anthropic-ai/claude-code,@anthropic-ai/sdk, or@anthropic-ai/tokenizer) is the target. Theclaude-token-tracker-mcpname aligns with the Mitiga Labs MCP token-theft attack chain in which a malicious npm package rewrites~/.claude.jsonon install to route Claude Code MCP traffic through an attacker localhost proxy, harvesting long-lived OAuth bearer tokens for every SaaS platform (Jira / Confluence / GitHub) the developer had connected. Anthropic told Mitiga the attack chain is out of scope pending user consent — no client-side patch will be shipped - Mid-July SDK-typosquat cluster (3 packages):
chain-sdk-js@1.0.2..1.0.6(2026-07-14 15:14 → 2026-07-15 21:30 UTC),theta-sdk-js@1.2.14..1.2.17(2026-07-10 12:57 → 16:37 UTC),ai-pro-sdk@2.0.1..2.0.4(2026-07-14 07:19 → 2026-07-16 07:39 UTC). All three share the same shape: SDK-suffix name, 3-6 rapid patch bumps in a single day, retired within 8 hours in the same npm-Security burst on 2026-07-16 23:29 → 23:55 UTC. Thechain-sdk-jsslug likely targets Chainlink / crypto chain-SDK developers;theta-sdk-jsmaps to the Theta Network blockchain SDK;ai-pro-sdkis a broader AI-SDK typosquat continuing theopenai-agents-helpers/anthropic-toolkit/ai-sdk-helperscluster Socket flagged on 2026-07-07 - June 15 P2P burst (3 packages):
ai-p2p@1.0.0..1.0.4,websight-p2p@1.0.0..1.0.6,websight2-p2p@1.0.0..1.0.4— all published within a 72-minute window on 2026-06-14 17:35 → 2026-06-15 19:44 UTC, retired in a 28-second npm-Security take-down burst on 2026-07-16 08:11:52 → 08:12:20 UTC. Shared version-numbering pattern (1.0.0→1.0.4/1.0.6rapid patch bumps within minutes of first publish), same day publication, same retirement burst — one operator broadening the dep-confusion catchment across three P2P/WebRTC-shaped internal-project slugs - Auto-publisher sleepers with mass version histories (3 packages):
px8my(55 versions across 1.0.0 → 1.0.54 — a daily-cadence auto-publisher running 2026-06-18 → 2026-07-16, roughly 30 days of schedulednpm publishcalls at similar times of day),monogrok(21 versions1.0.1 → 1.0.44across 2026-06-10 → 2026-07-16),scan-only(16 versions0.2.0 → 1.0.0in a ~2-hour burst on 2026-06-17 12:27 → 18:24 UTC).px8my's 30-day version cadence is unusual for a dep-confusion typosquat — it fits either (a) a compromised legitimate maintainer account with an auto-publish pipeline, or (b) an attacker-run test harness that got weaponized in the last few versions.scan-onlyis likely a security-tool internal name (aligns with a "scan-only mode" static-analyzer feature slug) that got typosquatted for a specific internal target - WordPress Gutenberg / terminal-toy fillers (4 packages):
my-tailwind-gutenberg-block@0.1.0..0.1.5(2026-07-16 same-day burst 16:31 → 21:00 UTC — the only package retired within hours of its first publish),awesome-terminal@1.0.1..1.0.4+terminal-mascot@1.0.0..3.5.3(both published 2026-07-11 08:00 → 08:47 UTC and retired 2026-07-16 23:31 → 23:54 UTC — same-hour publish coordination),wordpad-text-ui@1.0.0..1.0.2(2026-06-16 02:35 → 02:43 UTC). Theterminal-mascotversion jump from1.0.3to3.5.2inside 30 minutes is the fingerprint of a version-race dep-confusion pin - Singletons (3 packages):
hehehe@1.0.0..2.0.2(an odd 2-generation package with1.0.xversions from 2026-05-05 → 2026-05-20 and2.0.1/2.0.2republished 2026-07-15 12:04 → 20:34 UTC — the2.0.xpayload is what triggered retirement),vor8zakon@1.0.0(single version 2026-06-15 14:36 UTC, retired 2026-07-16 07:27 UTC — likely a Russian-language internal slug,vor= "thief" / "zakon" = "law"),loader1@2.1.2..2.1.7(2026-06-15 20:13 → 21:25 UTC 6-version burst) - No payload write-up accompanies the GHSA texts for any of these 18 packages — defenders should treat install-time behavior as unanalyzed and assume worst case for any host that resolved these names
What to do
- 1Grep every lockfile (
package-lock.json,yarn.lock,pnpm-lock.yaml) for each name in the packages map below. Any match is a supply-chain incident: rotate every credential the build runner could reach and re-image the build host - 2If your project imports
anthropic-claude-latestorclaude-token-tracker-mcp: replace with the canonical Anthropic-published packages —@anthropic-ai/claude-code,@anthropic-ai/sdk,@anthropic-ai/tokenizer,@anthropic-ai/bedrock-sdk, or@anthropic-ai/vertex-sdk. Always verify the@anthropic-ai/scope prefix. Forclaude-token-tracker-mcpspecifically: audit~/.claude.jsonon every developer workstation for unexpected MCP server URLs pointing atlocalhost:*proxies (per the Mitiga Labs attack chain — the malicious postinstall hook rewrites the file to route MCP traffic through an attacker-controlled localhost proxy). Rotate every OAuth token the Claude Code session had access to: GitHub, Jira, Confluence, and any other SaaS-connected MCP server - 3If you had
chain-sdk-js,theta-sdk-js, orai-pro-sdkin a lockfile: these are typosquats of well-known ecosystem SDKs. Use the canonical@chainlink/contracts,@theta-labs/theta-js, or theai(@vercel/ai-sdk) /openai/@anthropic-ai/sdkpackages depending on which real SDK you actually needed. Remove the malicious dependencies and rotate any credentials the CI environment could reach — build-time postinstall hooks reach cloud metadata, secrets stores, and any environment variables loaded by the runner - 4If you had
ai-p2p,websight-p2p, orwebsight2-p2pin a lockfile: none of these have a legitimate first-party parent on npm. These are internal-project dep-confusion pins. Register the-p2p-suffix namespaces as defensive stubs on the public registry (npm publishan empty@yourorg/p2p-*package) and pin the internal registry as the primary source via.npmrcscope-registry routing - 5If you had
px8my,monogrok, orscan-onlyin a lockfile: audit the 55/21/16 concrete versions individually (see packages map below).px8my's 30-day auto-publish cadence means many teams pulled it into an automated dependency-refresh PR at some point during the window.scan-onlyin particular is likely to be a security-tool internal name — check whether your organization has an internalscan-onlypackage on a private registry that this attacker was trying to dep-confuse - 6If you had any of the terminal-toy / WordPress / singleton fillers (
awesome-terminal,terminal-mascot,wordpad-text-ui,my-tailwind-gutenberg-block,hehehe,vor8zakon,loader1): none have legitimate first-party parents. Remove; treat as a supply-chain incident. Formy-tailwind-gutenberg-blockspecifically: audit any WordPress Gutenberg build pipeline that resolved this dependency — it was published and retired the same day, so the exposure window is narrow but the target is a WordPress plugin build chain with elevated CI access - 7Verify none of the 18 listed packages still resolves via your private mirror — internal Artifactory / Nexus / Verdaccio instances routinely cache tarballs and will keep serving the malicious versions after the public yank
- 8For projects using
postinstall-scripting packages, consider runningnpm install --ignore-scriptsin CI as a defense-in-depth measure and re-invoking scripts only for vetted first-party packages (the upcoming npm v12 defaults do this, per the npm v12 announcement)
References
- GitHubGitHub Advisory Database — recent npm malware advisoriesgithub.com
- GitHubGHSA-j588-p757-86r9 — anthropic-claude-latest malware advisorygithub.com
- GitHubGHSA-w56m-5ch4-5xjw — claude-token-tracker-mcp malware advisorygithub.com
- Mitiga LabsMCP Token Theft in Claude Code: A Man-in-the-Middle Attack Chainmitiga.io
- GitHubGHSA-2p8p-vrrr-9f6c — chain-sdk-js malware advisorygithub.com
- GitHubGHSA-qj2r-27rj-cc82 — theta-sdk-js malware advisorygithub.com
- GitHubGHSA-pw5v-v543-v4mp — ai-pro-sdk malware advisorygithub.com
- GitHubGHSA-g5cv-hmr5-x42p — ai-p2p malware advisorygithub.com
- GitHubGHSA-f4xq-pw58-878h — websight-p2p malware advisorygithub.com
- GitHubGHSA-jqc8-qp8m-m77v — websight2-p2p malware advisorygithub.com
- GitHubGHSA-9869-r2r5-fff6 — px8my malware advisorygithub.com
- GitHubGHSA-548c-qh8j-h895 — monogrok malware advisorygithub.com
- GitHubGHSA-72g3-g9xj-wxp6 — scan-only malware advisorygithub.com
- GitHubGHSA-mhvw-mw3c-6mc5 — my-tailwind-gutenberg-block malware advisorygithub.com
- GitHubGHSA-cv56-pvc8-j5rg — awesome-terminal malware advisorygithub.com
- GitHubGHSA-g2cj-hj2c-phvf — terminal-mascot malware advisorygithub.com
- GitHubGHSA-83j8-j97r-9p9h — wordpad-text-ui malware advisorygithub.com
- GitHubGHSA-f5qh-v92x-xcxj — hehehe malware advisorygithub.com
- GitHubGHSA-9f89-97fj-pqmp — vor8zakon malware advisorygithub.com
- GitHubGHSA-wp48-4xqv-v7fq — loader1 malware advisorygithub.com