Feed
HighPublished 27 Jul 202646 packages · 114 versions

GitHub Advisory npm CWE-506 sweep — 47-package overnight batch (8-package `thirdweb` / `rainbowkit` crypto-wallet typosquat cluster, 6-package baileys/WhatsApp-scraper `fazz*` + `@vinnxcode` + `sixbails` family, 4-package `log-taker` / `ts-escrow` sibling cluster, 5-package `txs-*` + `chai-log` operator cluster, 3-package `@403name/*` typosquat cluster, 4-package `edu-npm-*` "educational" postinstall family, `@wrenfield/abitype` + `@wrenfield/viem` crypto-SDK typosquats, `@kalipto/local` + `kalipto-runtime`, `@ceeferenderer/*` dep-confusion pair, `ap3-components-ui` v9.999.0 dep-confusion, `permcserver` / `permcarmserver`, plus singletons) retired 2026-07-27 01:02–05:36 UTC

Summary

On 2026-07-27 01:02 → 05:36 UTC GitHub retired 47 npm CWE-506 malware advisories in a single overnight batch. Twelve clusters spanning crypto-wallet typosquats (thirdweb / rainbowkit / @wrenfield/viem), WhatsApp-Baileys scrapers (fazz*, @vinnxcode, sixbails, amanexzyra-baileys), dependency-confusion (ap3-components-ui@9.999.0, @ceeferenderer/*), postinstall droppers (txs-*, chai-log, edu-npm-*, @403name/*), plus singletons. All 47 packages security-replaced with 0.0.1-security sentinel tarballs.

typosquatcrypto-wallet-draincredential-theftdependency-confusioninfostealer
Detected by
GitHub Advisory Database · npm Security
Also known as
2026-07-27 GHSA npm overnight sweep · thirdweb rainbowkit typosquat cluster · fazz/vinnxcode baileys family follow-on
Ecosystems
npm
Packages tracked
46

What happened

On 2026-07-27 between 01:02 and 05:36 UTC, GitHub's Advisory Database published 50 new CWE-506 (Embedded Malicious Code) advisories against npm packages in a single overnight batch. This module catalogues 47 of the 50 (the remaining 3 — @thone33/analytics-injector, @thone33/core-utils, @thone33/react-helpers — are absorbed into the pre-existing npm-2026-06-28-thone33-c2-stager-cluster record; polymarket-stake-maths is absorbed into npm-2026-07-17-polymarket-trap-clob-client-math). All 47 records use the standard CWE-506 boilerplate "any computer that has this package installed or running should be considered fully compromised — rotate all secrets from a different computer" and were security-replaced by the npm-support team on 2026-07-27 between 01:02:28 UTC (fazzgram) and 05:36:35 UTC (fluterjs).

Unlike a typical daily sweep, this batch spans ~19 weeks of prior publisher activity — from @ceeferenderer/fe-renderer-sdk@9.9.0 (published 2026-03-13, 137 days of dormancy) through ap3-components-ui@9.999.0 (published 2026-07-10, 17 days of dormancy) to fresh drops like the @vinnxcode scope (published 2026-07-16, 11 days of dormancy). The batch shape strongly suggests a coordinated take-down operation by npm-security against multiple long-running clusters, likely triggered by a signal upstream (Amazon Inspector, OpenSSF Package Analysis, or a security-vendor tip) rather than a fresh attack burst.

Cluster 1 — thirdweb / rainbowkit crypto-wallet SDK typosquats (8 packages)

| Package | Version | Publish (UTC) | npm security-replace (UTC) | |---|---|---|---| | rainbokit | 0.0.8 | 2026-06-19 08:19:25 | 2026-07-27 01:16:24 | | rainbownkit | 0.0.8 | 2026-06-19 08:19:42 | 2026-07-27 01:16:29 | | therdweb | 0.0.8 | 2026-06-19 09:06:29 | 2026-07-27 01:16:34 | | thidweb | 0.0.8 | 2026-06-19 09:06:45 | 2026-07-27 01:16:39 | | thirdwb | 0.0.8 | 2026-06-19 09:06:16 | 2026-07-27 01:16:44 | | thirdwebb | 0.0.8 | 2026-06-19 09:05:28 | 2026-07-27 01:16:49 | | thirdwebjs | 0.0.8 | 2026-06-19 09:05:56 | 2026-07-27 01:16:54 | | thurdweb | 0.0.8 | 2026-06-19 09:07:07 | 2026-07-27 01:16:59 |

All eight packages published within a 48-minute window on 2026-06-19 (8:19 → 9:07 UTC) using the same 0.0.8 version tag (deliberately chosen to appear as a "patch" of an existing legitimate package). The legitimate thirdweb npm package is a Web3 SDK with millions of weekly downloads; @rainbow-me/rainbowkit is the most popular Ethereum wallet-connect React library. The operator generated every plausible one-character permutation of the target names — anyone autocomplete-typing thirdweb in package.json has six near-misses to hit. All eight packages security-replaced within a 35-second window on 2026-07-27 01:16:24 → 01:16:59 UTC, confirming npm-security handled them as a single incident.

Cluster 2 — WhatsApp-Baileys credential-scraper family (6 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | @fazzcode/baileys | 11 versions (0.1.12.5.7) | 2026-01-25 → 2026-06-21 | 2026-07-27 01:02:39 | | sixbails | 12 versions (1.0.01.1.2) | 2026-06-19 → 2026-07-12 | 2026-07-27 01:08:46 | | amanexzyra-baileys | 3 versions (3.0.0, 4.0.0, 4.0.2) | 2026-06-22 → 2026-06-29 | 2026-07-27 01:03:24 | | @vinnxcode/libsignal-node | 2 versions (1.0.0, 1.0.1) | 2026-07-16 09:38 → 10:05 | 2026-07-27 01:08:56 | | @vinnxcode/xbailsync | 2 versions (1.0.0, 1.0.1) | 2026-07-16 10:10 → 10:25 | 2026-07-27 01:09:05 | | fazzanime | 3 versions (0.3.20.3.4) | 2026-05-24 | 2026-07-27 01:02:28 | | fazzgram | 2 versions (0.1.0, 0.1.1) | 2026-05-28 | 2026-07-27 01:02:43 |

All six packages fit the profile of the malicious-Baileys-fork family previously documented by Xygeni ("Malicious npm Package in Baileys Fork") and Koi Security ("NPM Package With 56K Downloads Caught Stealing WhatsApp Messages"). The legitimate @whiskeysockets/baileys is a WhatsApp Web scraper library; malicious forks add code that reads the ./auth_info_baileys/ session-state files on activate() and exfiltrates them to a C2. @fazzcode/baileys has by far the longest publish history (six months, 11 versions from 2026-01-25) — likely a legitimate account that was compromised, or a long-play trojan-horse account that seeded benign releases before injecting the payload.

The sibling npm-2026-07-15-ghsa-malware-sweep module catalogues the same-family @sauruslord/baileys / zaldy-baileys / sauruslord-baileys cluster taken down 2026-07-15. This 2026-07-27 batch appears to be the follow-up sweep catching the survivors that were missed in the first pass.

Cluster 3 — log-taker / ts-escrow sibling cluster (4 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | log-taker | 4 versions (0.0.70.1.0) | 2026-06-19 06:24 → 07:54 | 2026-07-27 01:16:19 | | log-taker1 | 0.1.0 | 2026-06-19 21:14:34 | 2026-07-27 01:17:14 | | ts-escrow | 2 versions (0.0.9, 0.1.0) | 2026-06-19 21:10 → 21:16 | 2026-07-27 01:17:24 | | ts-escro | 4 versions (0.0.60.0.9) | 2026-06-19 06:25 → 07:51 | 2026-07-27 01:17:05 |

Same 2026-06-19 publish date as Cluster 1 — the log-taker/ts-escro pair at 06:24/06:25 UTC and the follow-on log-taker1/ts-escrow pair at 21:14/21:10 UTC. The typo pair ts-escrow/ts-escro is a canonical single-character-off typosquat; the log-taker/log-taker1 pair uses a numeric suffix (a signature of a re-drop after the first name attracted flagging). Same-day publishing plus same-day take-down clustering with the thirdweb batch on 2026-07-27 01:16 UTC (all four packages security-replaced within 65 seconds of the thirdweb cluster) suggests operator overlap.

Cluster 4 — txs-* + chai-log operator cluster (5 packages)

| Package | Versions | Publish (UTC) | npm security-replace (UTC) | |---|---|---|---| | txs-builder | 1.0.6 | 2026-06-25 08:51:27 | 2026-07-27 01:22:05 | | txs-sdk-lib | 1.0.1 | 2026-07-10 07:25:25 | 2026-07-27 01:19:39 | | txs-random-lib | 1.0.1 | 2026-07-10 07:16:58 | 2026-07-27 01:20:19 | | txs-runner-lib | 1.0.1 | 2026-07-10 07:03:57 | 2026-07-27 01:21:07 | | chai-log | 1.1.0 | 2026-07-10 07:09:33 | 2026-07-27 01:18:04 |

The three txs-*-lib packages plus chai-log all published within a 22-minute window on 2026-07-10 07:03–07:25 UTC — a signature of an automated same-account publishing script. txs-builder@1.0.6 was published 15 days earlier by (likely) the same operator as a first-drop test. The txs-* naming mimics transaction-processing tooling (Ethereum tx builders, transaction runners); chai-log typosquats the Chai test framework as a "logging plugin". All five security-replaced within 4 minutes on 2026-07-27 01:18–01:22 UTC.

Cluster 5 — @403name/* typosquat cluster (3 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | @403name/electron-buidler | 1.0.01.0.2 | 2026-06-07 20:54:50 → 21:03:24 | 2026-07-27 01:30:38 | | @403name/ether-js | 1.0.01.0.2 | 2026-06-07 20:54:49 → 21:03:24 | 2026-07-27 01:30:47 | | @403name/fsevent | 1.0.01.0.2 | 2026-06-07 20:54:49 → 21:03:24 | 2026-07-27 01:30:56 |

Same-account scope publishing — all three packages published in a 9-minute window on 2026-06-07 20:54 → 21:03 UTC, then updated in lockstep to 1.0.1 (all at 20:56:51–20:56:52 UTC) and 1.0.2 (all at 21:03:24 UTC). The one-second inter-publish gap in each round is a signature of a scripted-publisher. Every package name typosquats a household-name dependency: fsevents (the macOS filesystem-events binding shipped as an optional dep in millions of Node projects), electron-builder (Electron packaging), ethers (Ethereum JavaScript SDK).

Cluster 6 — edu-npm-* "educational" postinstall family (4 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | edu-npm-helper-alpha | 1.0.0 | 2026-06-11 07:40:15 | 2026-07-27 01:26:36 | | edu-npm-helper-beta | 1.0.0 | 2026-06-11 07:40:33 | 2026-07-27 01:26:41 | | edu-npm-dependency-chain-demo | 1.0.01.0.4 (5 versions) | 2026-06-11 07:54:37 → 08:23:30 | 2026-07-27 01:26:31 | | edu-npm-postinstall-demo2 | 1.0.01.0.3 (4 versions) | 2026-06-11 07:54:00 → 08:23:10 | 2026-07-27 01:26:46 |

All four packages published within a 43-minute window on 2026-06-11 07:40 → 08:23 UTC. GHSA-flagged as CWE-506 despite the "educational" naming — the packages exercise real postinstall / dependency-chain exec primitives and any lockfile picking them up runs the demonstration payload on install. Nobody legitimately depends on an edu-npm-* name, so any hit represents intentional installation for research or a compromised research-tool leak into production.

Cluster 7 — @wrenfield crypto-SDK typosquats (2 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | @wrenfield/abitype | 1.2.3, 1.2.4, 1.2.6, 1.2.7 | 2026-06-21 00:55 → 2026-06-22 09:36 | 2026-07-27 01:06:23 | | @wrenfield/viem | 2.53.12.53.4 | 2026-06-21 00:57 → 2026-06-22 09:41 | 2026-07-27 01:06:32 |

Both packages use the exact then-current version numbers of the legitimate abitype (1.2.x series) and viem (2.53.x series) — the operator deliberately semver-aligned so that a lockfile refresh with a caret range against a mirror that resolved from a global feed would treat them as "one minor bump" from the legitimate release. viem and abitype are the core dependencies of the wagmi Ethereum React tooling ecosystem; any developer wiring up on-chain interactions is likely to touch both.

Cluster 8 — kalipto (2 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | kalipto-runtime | 1.0.0 | 2026-06-14 05:26:45 | 2026-07-27 05:32:26 | | @kalipto/local | 1.0.01.0.3 | 2026-06-14 06:39 → 07:03 | 2026-07-27 05:32:56 |

No clear legitimate kalipto upstream — likely an internal-tooling brand impersonation attempt or a niche framework typosquat. Both packages published on 2026-06-14 within a 1.5-hour window; security-replaced within 30 seconds of each other on 2026-07-27.

Cluster 9 — @ceeferenderer/* dep-confusion pair (2 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | @ceeferenderer/fe-renderer-sdk | 9.9.0, 9.9.9, 99.9.9 | 2026-03-13 01:07 → 2026-03-14 19:08 | 2026-07-27 01:04:31 | | @ceeferenderer/itg-renderer-sdk | 9.9.0, 9.9.9, 99.9.9 | 2026-03-13 01:07 → 2026-03-14 19:08 | 2026-07-27 01:04:41 |

137 days of dormancy — the oldest packages in this batch. The absurdly-inflated version numbers (9.9.0, 9.9.9, culminating in 99.9.9) are the textbook dependency-confusion signature: the attacker guesses at an internal package name at a specific organisation and publishes a version high enough that any semver-caret resolution against a public registry mirror would pull the malicious public version over the private one. Both scope members follow the same publish cadence and version-inflation pattern.

Cluster 10 — permc*server (2 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | permcserver | 1.0.01.0.4 | 2026-07-08 21:49 → 2026-07-14 14:45 | 2026-07-27 01:15:14 | | permcarmserver | 1.0.0 | 2026-07-12 06:50:10 | 2026-07-27 01:15:09 |

No clear upstream target; the -server suffix suggests server-daemon impersonation. Both packages security-replaced within 5 seconds on 2026-07-27 01:15:09 → 01:15:14 UTC, confirming npm-support handled them as a single cluster.

Singleton dep-confusion — ap3-components-ui@9.999.0

Published 2026-07-10 05:09:31 UTC as a single 9.999.0 version — a textbook dep-confusion attempt targeting an internal ap3-components-ui package name (likely a private component library at a specific organisation). Security-replaced 2026-07-27 02:37:44 UTC.

Singletons

| Package | Version(s) | Publish (UTC) | npm security-replace (UTC) | |---|---|---|---| | fluterjs | 1.0.0 | 2026-06-29 21:50:48 | 2026-07-27 05:36:35 | | jextic-eclib | 1.0.0 | 2026-06-11 19:19:01 | 2026-07-27 02:38:44 | | roblox-api-client | 1.0.0 | 2026-06-14 00:30:43 | 2026-07-27 01:27:15 | | npx-whoami-demo | 1.0.0 | 2026-06-14 12:09:07 | 2026-07-27 05:26:22 | | @ci-lifecycle-test/postinstall-ping | 1.0.0 | 2026-06-12 21:57:29 | 2026-07-27 02:40:19 | | v018-axios-cdntest | 1.0.01.0.3 (4 versions) | 2026-06-08 20:49 → 2026-06-09 06:18 | 2026-07-27 01:23:53 |

fluterjs typosquats Flutter (although Flutter is a Dart framework, not JS). roblox-api-client targets Roblox game-dev tooling. npx-whoami-demo and @ci-lifecycle-test/postinstall-ping present as demo / test packages but earned CWE-506 classification, so the demonstrated behaviour is malicious. v018-axios-cdntest — despite the "cdntest" naming — delivered live malware (4 versions across 10 hours on 2026-06-08 → 2026-06-09).

Registry state

All 47 packages security-replaced with 0.0.1-security sentinel tarballs. Original version tarballs are no longer resolvable on the public registry, but private registry mirrors that cached the tarballs during the publish windows (some dating back to 2026-03 for the @ceeferenderer/* pair) WILL keep serving the original versions after the public yank — any lockfile hit must be treated as actionable regardless of what the public registry currently returns.

Related tracked activity

  • The same 2026-07-27 batch included 3 more packages under the @thone33 scope (@thone33/analytics-injector, @thone33/core-utils, @thone33/react-helpers) — these are catalogued in the pre-existing npm-2026-06-28-thone33-c2-stager-cluster module which was updated on this ingest to add @thone33/react-helpers.
  • polymarket-stake-maths was likewise in the batch; it is catalogued in npm-2026-07-17-polymarket-trap-clob-client-math (updated to add the trailing-s sibling of the tracked polymarket-stake-math).
  • The Baileys-family cluster (Cluster 2) is a direct follow-on to the npm-2026-07-15-ghsa-malware-sweep @sauruslord/* / zaldy-baileys sweep — same-family payload behaviour, later takedown pass catching the survivors.

Affected packages (46)

  • npm@403name/electron-buidler
    1.0.01.0.11.0.2
  • npm@403name/ether-js
    1.0.01.0.11.0.2
  • npm@403name/fsevent
    1.0.01.0.11.0.2
  • npm@ceeferenderer/fe-renderer-sdk
    9.9.09.9.999.9.9
  • npm@ceeferenderer/itg-renderer-sdk
    9.9.09.9.999.9.9
  • npm@ci-lifecycle-test/postinstall-ping
    1.0.0
  • npm@fazzcode/baileys
    0.1.10.1.50.1.60.1.72.0.62.4.42.5.32.5.42.5.52.5.62.5.7
  • npm@kalipto/local
    1.0.01.0.11.0.21.0.3
  • npm@vinnxcode/libsignal-node
    1.0.01.0.1
  • npm@vinnxcode/xbailsync
    1.0.01.0.1
  • npm@wrenfield/abitype
    1.2.31.2.41.2.61.2.7
  • npm@wrenfield/viem
    2.53.12.53.22.53.32.53.4
  • npmamanexzyra-baileys
    3.0.04.0.04.0.2
  • npmap3-components-ui
    9.999.0
  • npmchai-log
    1.1.0
  • npmedu-npm-dependency-chain-demo
    1.0.01.0.11.0.21.0.31.0.4
  • npmedu-npm-helper-alpha
    1.0.0
  • npmedu-npm-helper-beta
    1.0.0
  • npmedu-npm-postinstall-demo2
    1.0.01.0.11.0.21.0.3
  • npmfazzanime
    0.3.20.3.30.3.4
  • npmfazzgram
    0.1.00.1.1
  • npmfluterjs
    1.0.0
  • npmjextic-eclib
    1.0.0
  • npmkalipto-runtime
    1.0.0
  • npmlog-taker
    0.0.70.0.80.0.90.1.0
  • npmlog-taker1
    0.1.0
  • npmnpx-whoami-demo
    1.0.0
  • npmpermcarmserver
    1.0.0
  • npmpermcserver
    1.0.01.0.11.0.21.0.31.0.4
  • npmrainbokit
    0.0.8
  • npmrainbownkit
    0.0.8
  • npmroblox-api-client
    1.0.0
  • npmsixbails
    1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.1.01.1.11.1.2
  • npmtherdweb
    0.0.8
  • npmthidweb
    0.0.8
  • npmthirdwb
    0.0.8
  • npmthirdwebb
    0.0.8
  • npmthirdwebjs
    0.0.8
  • npmthurdweb
    0.0.8
  • npmts-escro
    0.0.60.0.70.0.80.0.9
  • npmts-escrow
    0.0.90.1.0
  • npmtxs-builder
    1.0.6
  • npmtxs-random-lib
    1.0.1
  • npmtxs-runner-lib
    1.0.1
  • npmtxs-sdk-lib
    1.0.1
  • npmv018-axios-cdntest
    1.0.01.0.11.0.21.0.3

Impact

  • Any host that installed any of the 47 packages listed below should be treated as fully compromised — every GHSA record uses the boilerplate CWE-506 "any computer that has this package installed or running should be considered fully compromised — rotate all secrets from a different computer" language, and no patched version exists
  • Cluster 1 — thirdweb / rainbowkit crypto-wallet SDK typosquats (8 packages, all 0.0.8, published 2026-06-19 08:19 → 09:07 UTC in a 48-minute burst): therdweb, thidweb, thirdwb, thirdwebb, thirdwebjs, thurdweb (all typosquats of the legitimate thirdweb Web3 SDK — the operator produced every plausible one-character permutation of the target name), plus rainbokit and rainbownkit (typosquats of @rainbow-me/rainbowkit, the popular Ethereum wallet-connect React library). A crypto developer autocomplete-typing npm install thirdweb and landing on any one of six near-misses is the intended vector; the 38-day dormancy on the registry (2026-06-19 → 2026-07-27) means anyone who pulled one of these into a build has had wallet material exposed for over a month
  • Cluster 2 — WhatsApp-Baileys credential-scraper family (6 packages): @fazzcode/baileys (11 versions across 2026-01-25 → 2026-06-21), sixbails (12 versions across 2026-06-19 → 2026-07-12), amanexzyra-baileys (3 versions across 2026-06-22 → 2026-06-29), @vinnxcode/libsignal-node + @vinnxcode/xbailsync (2026-07-16), fazzanime (2026-05-24), fazzgram (2026-05-28). All fit the pattern of the Xygeni-tracked Baileys-fork infostealer family (see the sibling npm-2026-07-15-ghsa-malware-sweep @sauruslord/baileys / zaldy-baileys cluster) — malicious forks of the legitimate @whiskeysockets/baileys WhatsApp Web scraper that add credential exfil or session hijack. @fazzcode/baileys in particular has the longest exposure — six months of active publishing before 2026-07-27 takedown
  • Cluster 3 — log-taker / ts-escrow sibling cluster (4 packages, published 2026-06-19 06:24 → 07:54 UTC): log-taker (0.0.70.1.0, 4 versions), log-taker1 (0.1.0), ts-escrow (0.0.9, 0.1.0), ts-escro (0.0.60.0.9, 4 versions). The typo pair ts-escrow/ts-escro mimics generic TypeScript escrow-contract tooling; log-taker/log-taker1 masquerades as logging utilities. Same 90-minute publish window as Cluster 1 (thirdweb) — highly likely the same operator across both crypto-adjacent typosquat vocabularies
  • *Cluster 4 — `txs- + chai-log operator cluster** (5 packages, published 2026-06-25 → 2026-07-10): txs-builder (1.0.6), txs-runner-lib, txs-random-lib, txs-sdk-lib (all 1.0.1), chai-log (1.1.0). The txs- names mimic transaction-processing tooling (on-chain tx builders); chai-log typosquats the chai test framework by suggesting a logging plugin. Cross-cluster publish-time alignment on 2026-07-10 07:03–07:25 UTC (three txs- packages within 22 minutes) plus chai-log` on the same day at 07:09 UTC strongly implicates a single automated publisher
  • *Cluster 5 — `@403name/ typosquat cluster** (3 packages, all 1.0.01.0.2, published 2026-06-07 20:54 → 21:03 UTC): @403name/fsevent (typosquat of fsevents, the macOS filesystem-events binding shipped as an optional dep in millions of projects), @403name/electron-buidler (typosquat of electron-builder), @403name/ether-js (typosquat of ethers). Same-account scope publishing — all three packages published within a 9-minute window and updated in lockstep to 1.0.1 then 1.0.2`
  • *Cluster 6 — `edu-npm- "educational" postinstall family** (4 packages, published 2026-06-11 07:40 → 08:23 UTC): edu-npm-helper-alpha, edu-npm-helper-beta (both 1.0.0), edu-npm-dependency-chain-demo (1.0.01.0.4, 5 versions), edu-npm-postinstall-demo2 (1.0.01.0.3, 4 versions). GHSA-flagged as CWE-506 despite the "educational" naming — the packages exercise real postinstall / dependency-chain exec primitives and any lockfile picking them up runs the demonstration payload on install. Nobody legitimately depends on an edu-npm-*` name, so any hit represents intentional installation for research or a compromised research-tool leak into production
  • Cluster 7 — @wrenfield crypto-SDK typosquats (2 packages, published 2026-06-21 → 2026-06-22): @wrenfield/abitype (1.2.3, 1.2.4, 1.2.6, 1.2.7 — using the exact 1.2.x version numbers of the current-line legitimate abitype), @wrenfield/viem (2.53.12.53.4 — matching the then-current viem 2.53.x line). Both target the wagmi/viem Ethereum tooling ecosystem; the semver-alignment with real releases is deliberate so lockfile-refresh workflows resolve them as "one minor bump" from the legitimate version
  • Cluster 8 — kalipto (2 packages, 2026-06-14): kalipto-runtime (1.0.0), @kalipto/local (1.0.01.0.3). No plausible legitimate kalipto upstream — likely an internal-tooling-brand impersonation attempt or a niche framework typosquat
  • *Cluster 9 — `@ceeferenderer/ dep-confusion pair** (2 packages, published 2026-03-13 → 2026-03-14 — 4-month dormancy before 2026-07-27 takedown): @ceeferenderer/fe-renderer-sdk, @ceeferenderer/itg-renderer-sdk, both 9.9.0 / 9.9.9 / 99.9.9`. The absurdly-inflated version numbers are the classic dependency-confusion signature — the attacker guesses at an internal package name and publishes a version high enough that any organisation using semver-caret resolution against a public registry would pull the malicious public version over the private one
  • *Cluster 10 — `permcserver** (2 packages, published 2026-07-08 → 2026-07-14): permcserver (1.0.01.0.4, 5 versions), permcarmserver (1.0.0). No clear upstream target — the -server` suffix suggests server-daemon impersonation
  • Singleton dep-confusion — ap3-components-ui@9.999.0 (published 2026-07-10 05:09 UTC): the single 9.999.0 version is a textbook dep-confusion attempt — an inflated version number targeting an internal ap3-components-ui package name (likely a private component library at a specific organisation). Any org using semver-caret resolution against a public registry mirror would pull this over their internal package on the next lockfile refresh
  • Singletonsfluterjs (Flutter typosquat, 2026-06-29), jextic-eclib, roblox-api-client, npx-whoami-demo, @ci-lifecycle-test/postinstall-ping, v018-axios-cdntest: mixed origins. v018-axios-cdntest in particular is worth flagging — the name suggests a test package for exercising axios via CDN, but the CWE-506 classification means it delivered live malware, not benign test content
  • None of the 47 packages have surviving version tarballs on the public npm registry — all replaced with 0.0.1-security sentinel tarballs between 2026-07-27 01:02 and 05:36 UTC. Private registry mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs during the various publish windows (some dating back to 2026-03) WILL keep serving the original versions after the public yank

What to do

  1. 1Grep every lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml) for each name in the packages map below. Any match is a supply-chain incident: rotate every credential the build runner could reach and re-image the build host
  2. 2Highest-priority remediation — thirdweb / rainbowkit typosquat cluster: if any of therdweb, thidweb, thirdwb, thirdwebb, thirdwebjs, thurdweb, rainbokit, rainbownkit appears in a lockfile, treat as a wallet-compromise event. Rotate every crypto wallet key, seed phrase, hot-wallet secret, and hardware-wallet PIN accessible from the dev host. Move funds via a clean device BEFORE attempting rotation. The 38-day exposure window means the wallet material may have been drained already — check on-chain balances first
  3. 3*If any `@wrenfield/ package appears**: same as above — the abitype/viem` typosquats are wagmi/viem ecosystem-facing crypto-wallet targeting. Rotate wallet material, then rotate any adjacent developer credentials (npm tokens, GitHub tokens, cloud CLI tokens)
  4. 4If any Baileys-fork package appears (@fazzcode/baileys, sixbails, amanexzyra-baileys, @vinnxcode/xbailsync, @vinnxcode/libsignal-node, fazzanime, fazzgram): the WhatsApp session cookie / auth-state files under ./auth_info_baileys/ are likely already exfiltrated. Rotate the paired WhatsApp account (logout all sessions from the WhatsApp mobile app, then re-pair with fresh QR), and treat any credentials handled by the bot process as compromised
  5. 5*If any `@403name/ package appears**: cross-check whether the intended dependency was fsevents (mistyped as @403name/fsevent), electron-builder (mistyped as @403name/electron-buidler), or ethers (mistyped as @403name/ether-js) — these are the canonical typosquats. All three versions (1.0.0, 1.0.1, 1.0.2`) are compromised
  6. 6*If any `txs- or chai-log package appears**: the same-day publish alignment on 2026-07-10 07:03–07:25 UTC implicates a single automated publisher; audit CI logs for npm install` runs on that window and rotate CI-runner credentials
  7. 7If ap3-components-ui@9.999.0 appears: this is dependency-confusion — you have an INTERNAL package named ap3-components-ui that a public-registry lookup outranked. Configure your registry client to scope-restrict private packages (.npmrc scope-to-registry mapping), then rebuild the lockfile against the private registry. Rotate any secrets that were reachable from build hosts that installed the 9.999.0 version
  8. 8*If any `@ceeferenderer/ package appears**: same as above — the 9.9.9 / 99.9.9` inflated version numbers are dep-confusion. Even though the packages were on the registry since 2026-03, the 4-month dormancy means the exposure window is longer than most; audit build-host activity from 2026-03-13 forward
  9. 9*If any `edu-npm-` package appears**: nobody legitimately depends on these — a hit indicates either a compromised research-tool leak into production or an intentional install by a developer who typed the name manually. Investigate the human commit that added the dependency
  10. 10For projects using postinstall-scripting packages, run npm install --ignore-scripts in CI as a defense-in-depth measure and invoke scripts only for vetted first-party packages
  11. 11Verify none of the 47 listed packages still resolves via your private mirror — internal Artifactory / Nexus / Verdaccio instances routinely cache tarballs and will keep serving the original versions after the public yank
  12. 12The sibling packages @thone33/analytics-injector, @thone33/core-utils, and @thone33/react-helpers were also in the 2026-07-27 batch — they are catalogued in npm-2026-06-28-thone33-c2-stager-cluster; polymarket-stake-maths was likewise in the batch and is catalogued in npm-2026-07-17-polymarket-trap-clob-client-math. Both are cross-referenced from this module rather than duplicated

References

npm-2026-07-27-ghsa-malware-sweep