GitHub Advisory malware sweep — 5-package AWS/CDK dependency-confusion cluster, `upjsma` 9-version 3-day burst, and 80-package `@gocortexio/npmgremlinbox-*` Cortex red-team validation kit swept 2026-07-20
On 2026-07-20 GitHub's Advisory Database retired 86 CWE-506 npm malware advisories in a single sweep. Highlights: a 5-package AWS/CDK dependency-confusion cluster (alb-lambda-cdk, s3-lambda-dynamodb-cdk, lambda-cloudwatch-cdk, iot-kfh-s3, lwc-slds-lbc) published within a 20-minute window on 2026-07-18 with high dep-confusion pins, upjsma (9 versions across 3 days), and the 80-package @gocortexio/npmgremlinbox-* red-team validation kit from the Palo Alto Networks Cortex ecosystem tooling org.
- Detected by
- GitHub Advisory Database · OpenSSF Package Analysis · npm Security
- Also known as
- 2026-07-20 GHSA npm sweep · AWS/CDK dep-confusion cluster · @gocortexio/npmgremlinbox red-team validation kit
- Ecosystems
- npm
- Packages tracked
- 86
What happened
On 2026-07-20 GitHub's Advisory Database published 86 CWE-506 (Embedded Malicious Code) advisories against npm packages in a single-day sweep — the largest single-day GHSA malware batch for npm since the 2026-05-11 TanStack burst. Every record uses the standard "any computer that has this package installed or running should be considered fully compromised — rotate all secrets from a different computer" boilerplate.
Cluster 1 — AWS/CDK dependency-confusion cluster (5 packages)
| Package | Version | Publish (UTC) | npm security-replace (UTC) | |---|---|---|---| | lwc-slds-lbc | 18.9.41 | 2026-07-17 07:40:40 | 2026-07-20 17:02:58 | | alb-lambda-cdk | 18.2.22 | 2026-07-18 16:01:56 | 2026-07-20 17:02:43 | | iot-kfh-s3 | 17.3.23 | 2026-07-18 16:03:14 | 2026-07-20 17:02:48 | | s3-lambda-dynamodb-cdk | 15.10.16 | 2026-07-18 16:04:02 | 2026-07-20 17:03:03 | | lambda-cloudwatch-cdk | 0.0.0 | 2026-07-18 16:12:39 | 2026-07-20 17:02:53 |
All five were npm-security-replaced with 0.0.1-security sentinel tarballs within a 30-second window at 2026-07-20 17:02:43 → 17:03:03 UTC. Four of the five were published within an 11-minute window on 2026-07-18 (alb-lambda-cdk first at 16:01:56 UTC, iot-kfh-s3 at 16:03:14 UTC, s3-lambda-dynamodb-cdk at 16:04:02 UTC, lambda-cloudwatch-cdk at 16:12:39 UTC); lwc-slds-lbc was staged earlier on 2026-07-17 at 07:40:40 UTC.
Extreme dep-confusion version pins
The version numbers — 18.2.22, 17.3.23, 18.9.41, 15.10.16 — fit the classic dependency-confusion pattern: pick a version higher than any plausible internal semver so a misconfigured resolver picks the public tarball over the private one. The one exception (lambda-cloudwatch-cdk@0.0.0) is the opposite tactic — a zero-version pin that some resolvers treat as "latest" for unpublished packages.
Target signal from the names
alb-lambda-cdk,s3-lambda-dynamodb-cdk,lambda-cloudwatch-cdk— AWS CDK construct libraries. The naming convention (<AWS service>-<related service>-cdk) matches enterprise-internal CDK construct patterns where teams publish@yourorg/alb-lambda-cdk-style scoped constructs.iot-kfh-s3— AWS IoT + S3, likely a Kinesis Firehose (kfh) bridging construct.lwc-slds-lbc— Salesforce Lightning Web Components + SLDS (Salesforce Lightning Design System) +lbc(likely an internal component library abbreviation). The Salesforce ecosystem convention for internal LWC packages is@yourorg-lwc/*or@yourorg/lwc-*.
Cluster 2 — upjsma 9-version 3-day burst (1 package)
| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | upjsma | 1.0.58 → 1.0.66 (9 versions) | 2026-07-18 03:15 → 2026-07-20 13:06 | 2026-07-20 19:29 |
Nine versions published across 3 days from 2026-07-18 03:15 UTC to 2026-07-20 13:06 UTC, then npm-security-replaced 2026-07-20 19:29 UTC. The sustained multi-day publish cadence — plus the tight version-58 → version-66 sequential burst across day boundaries — fits a semver-race dependency-confusion pattern where the operator keeps incrementing the patch level to survive a specific resolver behavior. All 9 versions share the same publisher signature and are flagged in the OpenSSF Package Analysis dataset for outbound network activity during install.
Cluster 3 — @gocortexio/npmgremlinbox-* Cortex red-team validation kit (80 packages)
Every package under the @gocortexio npm scope — a total of 80 packages — was published on 2026-07-05 (v2.1.0), with some additionally carrying v2.0.1 from 2026-07-04, then npm-security-replaced en masse at 2026-07-20 02:50 → 02:55 UTC.
Origin: gocortex.io independent tools org
The @gocortexio scope belongs to github.com/gocortexio — self-described in their org bio as "Independent tools, projects, and ideas to complement and extend the Palo Alto Networks Cortex eco-system." The org publishes tools including gocortexbrokenbank (intentionally-vulnerable app for security training), signalbench (Rust endpoint telemetry generator aligned with MITRE ATT&CK), spellbook (Cortex content pack development tooling), xdrtop (Cortex XSIAM/XDR terminal monitor), and skills (portable skill bundles for the Cortex Platform).
Package naming pattern reveals research intent
The 80 npmgremlinbox-* packages cluster into three thematic groups:
- SPDX license identifiers (~60 packages):
agpl-3-0,agpl-1-0,agpl-1-0-only,agpl-1-0-or-later,agpl-3-0-only,agpl-3-0-or-later,apsl,arphic-1999,artistic-1-0,busl-1-1,c-uda-1-0,cal-1-0-combined-work-exception,cc-by-nc-3-0-de,cc-by-nc-nd-3-0-de,cc-by-nc-nd-3-0-igo,cc-by-nc-sa-2-0-de,cc-by-nc-sa-2-0-fr,cc-by-nc-sa-2-0-uk,cc-by-nc-sa-3-0-de,cc-by-nc-sa-3-0-igo,cc-by-nd-3-0-de,cc-by-sa-2-0-uk,cc-by-sa-2-1-jp,cc-by-sa-3-0-at,cc-by-sa-3-0-de,cc-by-sa-4-0,cddl-1-0,cdla-sharing-1-0,cern-ohl-s-2-0,cern-ohl-w-2-0,copyleft-next-0-3-0,copyleft-next-0-3-1,cpol-1-02,ecos-2-0,epl-1-0,epl-2-0,eupl-1-1,eupl-1-2,eupl-3-0,fdk-aac,gpl-2-0,gpl-3-0,hippocratic-2-1,jpl-image,lgpl-2-0,lgpl-2-1,lgpl-3-0,linux-man-pages-copyleft,mpl-1-1,mpl-2-0,ms-lpl,ncgl-uk-2-0,openpbs-2-3,osl-3-0,polyform-noncommercial-1-0-0,polyform-small-business-1-0-0,qpl-1-0-inria-2004,sendmail-8-23,simpl-2-0,sspl-1-0,tapr-ohl-1-0,tpl-1-0,ucl-1-0,unlicense,wxwindows,base. - Popular-library typosquats (8 packages):
typosquat-axios,typosquat-chalk,typosquat-commander,typosquat-express,typosquat-lodash,typosquat-moment,typosquat-react,typosquat-webpack. - Self-labeled malware indicators (6 packages):
malware-c2-beacon,malware-code-obfuscation,malware-credential-harvesting,malware-cryptomining-indicators,malware-install-execution,malware-network-indicators.
Interpretation: Cortex XSIAM npm malware detection validation kit
The naming pattern reads unmistakably as a controlled test suite for validating a security scanner's coverage across npm-attack pattern categories: license-based publisher metadata scanning, typosquat detection, and behavioral indicators (C2 beaconing, credential harvesting, code obfuscation, cryptomining, install-time execution, network indicators). This looks like a Cortex XSIAM validation kit rather than active attack malware — an interpretation supported by the gocortex.io org's public-facing role as a Cortex tooling developer.
However, GHSA has classified every package as CWE-506 malware, npm has security-replaced all 80 tarballs, and the packages should not appear in any production dependency graph regardless of intent. If a lockfile contains any @gocortexio/npmgremlinbox-* name, either your CI is inadvertently pulling in test-suite artifacts (fix the resolver / registry filter), or your organization is deliberately exercising Cortex's test kit against a benchmark corpus (in which case document the intended use so future scanner runs don't re-flag it).
Registry state
All 86 packages were npm-security-replaced (0.0.1-security sentinel tarball at latest dist-tag). Original version tarballs are no longer resolvable on the public registry, but private registry mirrors that cached the tarballs during the publish window WILL keep serving the original versions after the public yank — any lockfile hit must be treated as actionable regardless of what the public registry currently returns.
Affected packages (86)
- npm
@gocortexio/npmgremlinbox-agpl-1-02.1.0 - npm
@gocortexio/npmgremlinbox-agpl-1-0-only2.1.0 - npm
@gocortexio/npmgremlinbox-agpl-1-0-or-later2.1.0 - npm
@gocortexio/npmgremlinbox-agpl-3-02.0.12.1.0 - npm
@gocortexio/npmgremlinbox-agpl-3-0-only2.1.0 - npm
@gocortexio/npmgremlinbox-agpl-3-0-or-later2.1.0 - npm
@gocortexio/npmgremlinbox-apsl2.1.0 - npm
@gocortexio/npmgremlinbox-arphic-19992.1.0 - npm
@gocortexio/npmgremlinbox-artistic-1-02.1.0 - npm
@gocortexio/npmgremlinbox-base2.1.0 - npm
@gocortexio/npmgremlinbox-busl-1-12.1.0 - npm
@gocortexio/npmgremlinbox-c-uda-1-02.1.0 - npm
@gocortexio/npmgremlinbox-cal-1-0-combined-work-exception2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-nc-3-0-de2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-nd-3-0-de2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-sa-2-0-uk2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-sa-2-1-jp2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-sa-3-0-at2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-sa-3-0-de2.1.0 - npm
@gocortexio/npmgremlinbox-cc-by-sa-4-02.1.0 - npm
@gocortexio/npmgremlinbox-cddl-1-02.1.0 - npm
@gocortexio/npmgremlinbox-cdla-sharing-1-02.1.0 - npm
@gocortexio/npmgremlinbox-cern-ohl-s-2-02.1.0 - npm
@gocortexio/npmgremlinbox-cern-ohl-w-2-02.1.0 - npm
@gocortexio/npmgremlinbox-copyleft-next-0-3-02.1.0 - npm
@gocortexio/npmgremlinbox-copyleft-next-0-3-12.1.0 - npm
@gocortexio/npmgremlinbox-cpol-1-022.1.0 - npm
@gocortexio/npmgremlinbox-ecos-2-02.1.0 - npm
@gocortexio/npmgremlinbox-epl-1-02.1.0 - npm
@gocortexio/npmgremlinbox-epl-2-02.1.0 - npm
@gocortexio/npmgremlinbox-eupl-1-12.1.0 - npm
@gocortexio/npmgremlinbox-eupl-1-22.1.0 - npm
@gocortexio/npmgremlinbox-eupl-3-02.1.0 - npm
@gocortexio/npmgremlinbox-fdk-aac2.1.0 - npm
@gocortexio/npmgremlinbox-gpl-2-02.1.0 - npm
@gocortexio/npmgremlinbox-gpl-3-02.1.0 - npm
@gocortexio/npmgremlinbox-hippocratic-2-12.1.0 - npm
@gocortexio/npmgremlinbox-jpl-image2.1.0 - npm
@gocortexio/npmgremlinbox-lgpl-2-02.1.0 - npm
@gocortexio/npmgremlinbox-lgpl-2-12.1.0 - npm
@gocortexio/npmgremlinbox-lgpl-3-02.1.0 - npm
@gocortexio/npmgremlinbox-linux-man-pages-copyleft2.1.0 - npm
@gocortexio/npmgremlinbox-malware-c2-beacon2.1.0 - npm
@gocortexio/npmgremlinbox-malware-code-obfuscation2.1.0 - npm
@gocortexio/npmgremlinbox-malware-credential-harvesting2.1.0 - npm
@gocortexio/npmgremlinbox-malware-cryptomining-indicators2.1.0 - npm
@gocortexio/npmgremlinbox-malware-install-execution2.1.0 - npm
@gocortexio/npmgremlinbox-malware-network-indicators2.1.0 - npm
@gocortexio/npmgremlinbox-mpl-1-12.1.0 - npm
@gocortexio/npmgremlinbox-mpl-2-02.1.0 - npm
@gocortexio/npmgremlinbox-ms-lpl2.1.0 - npm
@gocortexio/npmgremlinbox-ncgl-uk-2-02.1.0 - npm
@gocortexio/npmgremlinbox-openpbs-2-32.1.0 - npm
@gocortexio/npmgremlinbox-osl-3-02.1.0 - npm
@gocortexio/npmgremlinbox-polyform-noncommercial-1-0-02.1.0 - npm
@gocortexio/npmgremlinbox-polyform-small-business-1-0-02.1.0 - npm
@gocortexio/npmgremlinbox-qpl-1-0-inria-20042.1.0 - npm
@gocortexio/npmgremlinbox-sendmail-8-232.1.0 - npm
@gocortexio/npmgremlinbox-simpl-2-02.1.0 - npm
@gocortexio/npmgremlinbox-sspl-1-02.1.0 - npm
@gocortexio/npmgremlinbox-tapr-ohl-1-02.1.0 - npm
@gocortexio/npmgremlinbox-tpl-1-02.1.0 - npm
@gocortexio/npmgremlinbox-typosquat-axios2.1.0 - npm
@gocortexio/npmgremlinbox-typosquat-chalk2.1.0 - npm
@gocortexio/npmgremlinbox-typosquat-commander2.1.0 - npm
@gocortexio/npmgremlinbox-typosquat-express2.1.0 - npm
@gocortexio/npmgremlinbox-typosquat-lodash2.1.0 - npm
@gocortexio/npmgremlinbox-typosquat-moment2.1.0 - npm
@gocortexio/npmgremlinbox-typosquat-react2.1.0 - npm
@gocortexio/npmgremlinbox-typosquat-webpack2.1.0 - npm
@gocortexio/npmgremlinbox-ucl-1-02.1.0 - npm
@gocortexio/npmgremlinbox-unlicense2.1.0 - npm
@gocortexio/npmgremlinbox-wxwindows2.1.0 - npm
alb-lambda-cdk18.2.22 - npm
iot-kfh-s317.3.23 - npm
lambda-cloudwatch-cdk0.0.0 - npm
lwc-slds-lbc18.9.41 - npm
s3-lambda-dynamodb-cdk15.10.16 - npm
upjsma1.0.581.0.591.0.601.0.611.0.621.0.631.0.641.0.651.0.66
Impact
- Any host that installed any of the packages below should be treated as fully compromised — every GHSA record uses the boilerplate CWE-506 "rotate all secrets from a different computer" language, and no patched version exists
- AWS/CDK dependency-confusion cluster (5 packages):
alb-lambda-cdk@18.2.22(published 2026-07-18 16:01:56 UTC),s3-lambda-dynamodb-cdk@15.10.16(published 2026-07-18 16:04:02 UTC),lambda-cloudwatch-cdk@0.0.0(published 2026-07-18 16:12:39 UTC),iot-kfh-s3@17.3.23(published 2026-07-18 16:03:14 UTC), andlwc-slds-lbc@18.9.41(published 2026-07-17 07:40:40 UTC) were all npm-security-replaced with0.0.1-securitytarballs within a 30-second window at 2026-07-20 17:02:43 → 17:03:03 UTC. The extreme version numbers (18.2.22,17.3.23,18.9.41,15.10.16) fit the classic dependency-confusion pattern — pick a version higher than any plausible internal semver so a misconfigured resolver picks the public tarball over the private one. Package names strongly suggest specific internal targets:alb-lambda-cdk/s3-lambda-dynamodb-cdk/lambda-cloudwatch-cdk/iot-kfh-s3look like AWS CDK construct libraries in an enterprise@yourorg/*scope;lwc-slds-lbcfits Salesforce Lightning Web Components (LWC + SLDS design tokens) internal naming upjsma9-version 3-day burst (1 package): 9 versions1.0.58→1.0.66published across 3 days from 2026-07-18 03:15 UTC → 2026-07-20 13:06 UTC, then npm-security-replaced 2026-07-20 19:29 UTC (about 6 hours after the final version pushed). The sustained multi-day publish cadence — plus the version-64 → version-66 continuation across day boundaries — is characteristic of a semver-race dependency-confusion pattern: the operator keeps incrementing the patch level to survive a specific resolver behavior (some resolvers cache-invalidate on version bump, others don't). All 9 versions share the same tarball fingerprint per the OpenSSF Package Analysis dataset and should be treated as equally malicious- *`@gocortexio/npmgremlinbox-
cluster** (80 packages): every package under the@gocortexionpm scope was swept in a coordinated npm-security-replacement at 2026-07-20 02:50 → 02:55 UTC. This cluster is the **npm-gremlinbox** red-team validation kit published by [gocortex.io](https://github.com/gocortexio) — an independent tools organization that ships Cortex XDR / XSIAM tooling for the Palo Alto Networks Cortex ecosystem. Package names include SPDX license identifiers (agpl-3-0,eupl-1-2,mpl-2-0,cc-by-sa-4-0,openpbs-2-3,qpl-1-0-inria-2004,sspl-1-0,hippocratic-2-1,busl-1-1,unlicense, ~60 more), popular-library typosquat names (typosquat-axios,typosquat-webpack,typosquat-lodash,typosquat-react,typosquat-express,typosquat-moment,typosquat-chalk,typosquat-commander), and self-labeled malware indicator names (malware-c2-beacon,malware-credential-harvesting,malware-code-obfuscation,malware-network-indicators,malware-install-execution,malware-cryptomining-indicators`). The naming pattern — and the org bio ("Independent tools, projects, and ideas to complement and extend the Palo Alto Networks Cortex eco-system") — strongly suggests this is a controlled test suite for validating Cortex XSIAM's npm malware detection coverage, but GHSA has classified every package as CWE-506 malware and npm has security-replaced all 80. Any lockfile hit still warrants investigation — even a benign research kit does not belong in a production dependency graph, and cache-poisoning risks apply equally to research-origin tarballs - None of the 86 packages have surviving version tarballs on the public npm registry — all replaced with
0.0.1-securitysentinel tarballs. Private registry mirrors (Verdaccio, Artifactory, Nexus) that cached the tarballs during the publish window WILL keep serving the original versions after the public yank — lockfile hits on these names must be treated as actionable regardless of what the public registry currently returns
What to do
- 1Grep every lockfile (
package-lock.json,yarn.lock,pnpm-lock.yaml) for each name in the packages map below. Any match is a supply-chain incident: rotate every credential the build runner could reach and re-image the build host - 2If you had
alb-lambda-cdk,s3-lambda-dynamodb-cdk,lambda-cloudwatch-cdk,iot-kfh-s3, orlwc-slds-lbcin a lockfile: this indicates a misconfigured internal-registry resolver — the names suggest your organization has (or once had) private@yourorg/*-scoped CDK constructs or an internal Salesforce Lightning tooling scope. Audit the resolver order in.npmrc(private registry MUST be listed before the public registry for internal-scope names), register defensive stubs on the public npm registry for every internal package name you care about, and consider migrating internal names to a scoped namespace (@yourorg/*) with.npmrcscope-registry routing so the public registry is never queried for these names - 3If you had
upjsmain a lockfile: any of the 9 versions1.0.58→1.0.66should be treated as compromised. Grep for all 9 pins individually — a lockfile that resolved to1.0.62(for example) is just as compromised as one that resolved to1.0.66, since the tarballs share the same publisher signature and OpenSSF-flagged behavioral fingerprint. Rotate every credential the CI environment could reach - 4*If you had any `@gocortexio/npmgremlinbox-
package in a lockfile**: this is very likely a Cortex red-team validation kit rather than active credential-stealing malware — the@gocortexioscope is [an independent tools organization](https://github.com/gocortexio) that publishes Cortex XDR / XSIAM tooling for the Palo Alto Networks Cortex ecosystem, and thenpmgremlinboxcluster reads as a controlled malware-detection benchmark suite (package names span SPDX license identifiers, popular-library typosquats, and self-labeled malware indicators). Even so, the packages should not be in a production dependency graph: remove them, verify none of your CI/CD workflows install from@gocortexio` unless deliberately intended, and confirm your Cortex tenant's test kit isn't inadvertently pulling into production builds - 5Verify none of the 86 listed packages still resolves via your private mirror — internal Artifactory / Nexus / Verdaccio instances routinely cache tarballs and will keep serving the original versions after the public yank
- 6For projects using
postinstall-scripting packages, consider runningnpm install --ignore-scriptsin CI as a defense-in-depth measure and re-invoking scripts only for vetted first-party packages
References
- GitHubGitHub Advisory Database — recent npm malware advisoriesgithub.com
- GitHubGHSA-crmc-3m53-3crf — alb-lambda-cdk malware advisorygithub.com
- GitHubGHSA-6xqw-c34f-9275 — s3-lambda-dynamodb-cdk malware advisorygithub.com
- GitHubGHSA-m74r-g438-3r92 — lambda-cloudwatch-cdk malware advisorygithub.com
- GitHubGHSA-qg52-c79f-3q5c — iot-kfh-s3 malware advisorygithub.com
- GitHubGHSA-xm8f-w286-57x5 — lwc-slds-lbc malware advisorygithub.com
- GitHubGHSA-9g67-fm87-8p6v — upjsma malware advisorygithub.com
- GitHubGHSA-pwfp-vhxq-7g8f — @gocortexio/npmgremlinbox-ms-lpl malware advisory (representative of the 80-package cluster)github.com
- GitHubGHSA-vmcc-vqgj-wh6c — @gocortexio/npmgremlinbox-malware-c2-beacon malware advisorygithub.com
- GitHubGHSA-2wfp-mw9m-3c6x — @gocortexio/npmgremlinbox-typosquat-lodash malware advisorygithub.com
- GoCortexIOGoCortexIO organization on GitHubgithub.com