GitHub Advisory npm CWE-506 sweep — 47-package overnight batch (8-package `thirdweb` / `rainbowkit` crypto-wallet typosquat cluster, 6-package baileys/WhatsApp-scraper `fazz*` + `@vinnxcode` + `sixbails` family, 4-package `log-taker` / `ts-escrow` sibling cluster, 5-package `txs-*` + `chai-log` operator cluster, 3-package `@403name/*` typosquat cluster, 4-package `edu-npm-*` "educational" postinstall family, `@wrenfield/abitype` + `@wrenfield/viem` crypto-SDK typosquats, `@kalipto/local` + `kalipto-runtime`, `@ceeferenderer/*` dep-confusion pair, `ap3-components-ui` v9.999.0 dep-confusion, `permcserver` / `permcarmserver`, plus singletons) retired 2026-07-27 01:02–05:36 UTC
On 2026-07-27 01:02 → 05:36 UTC GitHub retired 47 npm CWE-506 malware advisories in a single overnight batch. Twelve clusters spanning crypto-wallet typosquats (thirdweb / rainbowkit / @wrenfield/viem), WhatsApp-Baileys scrapers (fazz*, @vinnxcode, sixbails, amanexzyra-baileys), dependency-confusion (ap3-components-ui@9.999.0, @ceeferenderer/*), postinstall droppers (txs-*, chai-log, edu-npm-*, @403name/*), plus singletons. All 47 packages security-replaced with 0.0.1-security sentinel tarballs.
- Detected by
- GitHub Advisory Database · npm Security
- Also known as
- 2026-07-27 GHSA npm overnight sweep · thirdweb rainbowkit typosquat cluster · fazz/vinnxcode baileys family follow-on
- Ecosystems
- npm
- Packages tracked
- 46
What happened
On 2026-07-27 between 01:02 and 05:36 UTC, GitHub's Advisory Database published 50 new CWE-506 (Embedded Malicious Code) advisories against npm packages in a single overnight batch. This module catalogues 47 of the 50 (the remaining 3 — @thone33/analytics-injector, @thone33/core-utils, @thone33/react-helpers — are absorbed into the pre-existing npm-2026-06-28-thone33-c2-stager-cluster record; polymarket-stake-maths is absorbed into npm-2026-07-17-polymarket-trap-clob-client-math). All 47 records use the standard CWE-506 boilerplate "any computer that has this package installed or running should be considered fully compromised — rotate all secrets from a different computer" and were security-replaced by the npm-support team on 2026-07-27 between 01:02:28 UTC (fazzgram) and 05:36:35 UTC (fluterjs).
Unlike a typical daily sweep, this batch spans ~19 weeks of prior publisher activity — from @ceeferenderer/fe-renderer-sdk@9.9.0 (published 2026-03-13, 137 days of dormancy) through ap3-components-ui@9.999.0 (published 2026-07-10, 17 days of dormancy) to fresh drops like the @vinnxcode scope (published 2026-07-16, 11 days of dormancy). The batch shape strongly suggests a coordinated take-down operation by npm-security against multiple long-running clusters, likely triggered by a signal upstream (Amazon Inspector, OpenSSF Package Analysis, or a security-vendor tip) rather than a fresh attack burst.
Cluster 1 — thirdweb / rainbowkit crypto-wallet SDK typosquats (8 packages)
| Package | Version | Publish (UTC) | npm security-replace (UTC) | |---|---|---|---| | rainbokit | 0.0.8 | 2026-06-19 08:19:25 | 2026-07-27 01:16:24 | | rainbownkit | 0.0.8 | 2026-06-19 08:19:42 | 2026-07-27 01:16:29 | | therdweb | 0.0.8 | 2026-06-19 09:06:29 | 2026-07-27 01:16:34 | | thidweb | 0.0.8 | 2026-06-19 09:06:45 | 2026-07-27 01:16:39 | | thirdwb | 0.0.8 | 2026-06-19 09:06:16 | 2026-07-27 01:16:44 | | thirdwebb | 0.0.8 | 2026-06-19 09:05:28 | 2026-07-27 01:16:49 | | thirdwebjs | 0.0.8 | 2026-06-19 09:05:56 | 2026-07-27 01:16:54 | | thurdweb | 0.0.8 | 2026-06-19 09:07:07 | 2026-07-27 01:16:59 |
All eight packages published within a 48-minute window on 2026-06-19 (8:19 → 9:07 UTC) using the same 0.0.8 version tag (deliberately chosen to appear as a "patch" of an existing legitimate package). The legitimate thirdweb npm package is a Web3 SDK with millions of weekly downloads; @rainbow-me/rainbowkit is the most popular Ethereum wallet-connect React library. The operator generated every plausible one-character permutation of the target names — anyone autocomplete-typing thirdweb in package.json has six near-misses to hit. All eight packages security-replaced within a 35-second window on 2026-07-27 01:16:24 → 01:16:59 UTC, confirming npm-security handled them as a single incident.
Cluster 2 — WhatsApp-Baileys credential-scraper family (6 packages)
| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | @fazzcode/baileys | 11 versions (0.1.1 → 2.5.7) | 2026-01-25 → 2026-06-21 | 2026-07-27 01:02:39 | | sixbails | 12 versions (1.0.0 → 1.1.2) | 2026-06-19 → 2026-07-12 | 2026-07-27 01:08:46 | | amanexzyra-baileys | 3 versions (3.0.0, 4.0.0, 4.0.2) | 2026-06-22 → 2026-06-29 | 2026-07-27 01:03:24 | | @vinnxcode/libsignal-node | 2 versions (1.0.0, 1.0.1) | 2026-07-16 09:38 → 10:05 | 2026-07-27 01:08:56 | | @vinnxcode/xbailsync | 2 versions (1.0.0, 1.0.1) | 2026-07-16 10:10 → 10:25 | 2026-07-27 01:09:05 | | fazzanime | 3 versions (0.3.2–0.3.4) | 2026-05-24 | 2026-07-27 01:02:28 | | fazzgram | 2 versions (0.1.0, 0.1.1) | 2026-05-28 | 2026-07-27 01:02:43 |
All six packages fit the profile of the malicious-Baileys-fork family previously documented by Xygeni ("Malicious npm Package in Baileys Fork") and Koi Security ("NPM Package With 56K Downloads Caught Stealing WhatsApp Messages"). The legitimate @whiskeysockets/baileys is a WhatsApp Web scraper library; malicious forks add code that reads the ./auth_info_baileys/ session-state files on activate() and exfiltrates them to a C2. @fazzcode/baileys has by far the longest publish history (six months, 11 versions from 2026-01-25) — likely a legitimate account that was compromised, or a long-play trojan-horse account that seeded benign releases before injecting the payload.
The sibling npm-2026-07-15-ghsa-malware-sweep module catalogues the same-family @sauruslord/baileys / zaldy-baileys / sauruslord-baileys cluster taken down 2026-07-15. This 2026-07-27 batch appears to be the follow-up sweep catching the survivors that were missed in the first pass.
Cluster 3 — log-taker / ts-escrow sibling cluster (4 packages)
| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | log-taker | 4 versions (0.0.7–0.1.0) | 2026-06-19 06:24 → 07:54 | 2026-07-27 01:16:19 | | log-taker1 | 0.1.0 | 2026-06-19 21:14:34 | 2026-07-27 01:17:14 | | ts-escrow | 2 versions (0.0.9, 0.1.0) | 2026-06-19 21:10 → 21:16 | 2026-07-27 01:17:24 | | ts-escro | 4 versions (0.0.6–0.0.9) | 2026-06-19 06:25 → 07:51 | 2026-07-27 01:17:05 |
Same 2026-06-19 publish date as Cluster 1 — the log-taker/ts-escro pair at 06:24/06:25 UTC and the follow-on log-taker1/ts-escrow pair at 21:14/21:10 UTC. The typo pair ts-escrow/ts-escro is a canonical single-character-off typosquat; the log-taker/log-taker1 pair uses a numeric suffix (a signature of a re-drop after the first name attracted flagging). Same-day publishing plus same-day take-down clustering with the thirdweb batch on 2026-07-27 01:16 UTC (all four packages security-replaced within 65 seconds of the thirdweb cluster) suggests operator overlap.
Cluster 4 — txs-* + chai-log operator cluster (5 packages)
| Package | Versions | Publish (UTC) | npm security-replace (UTC) | |---|---|---|---| | txs-builder | 1.0.6 | 2026-06-25 08:51:27 | 2026-07-27 01:22:05 | | txs-sdk-lib | 1.0.1 | 2026-07-10 07:25:25 | 2026-07-27 01:19:39 | | txs-random-lib | 1.0.1 | 2026-07-10 07:16:58 | 2026-07-27 01:20:19 | | txs-runner-lib | 1.0.1 | 2026-07-10 07:03:57 | 2026-07-27 01:21:07 | | chai-log | 1.1.0 | 2026-07-10 07:09:33 | 2026-07-27 01:18:04 |
The three txs-*-lib packages plus chai-log all published within a 22-minute window on 2026-07-10 07:03–07:25 UTC — a signature of an automated same-account publishing script. txs-builder@1.0.6 was published 15 days earlier by (likely) the same operator as a first-drop test. The txs-* naming mimics transaction-processing tooling (Ethereum tx builders, transaction runners); chai-log typosquats the Chai test framework as a "logging plugin". All five security-replaced within 4 minutes on 2026-07-27 01:18–01:22 UTC.
Cluster 5 — @403name/* typosquat cluster (3 packages)
| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | @403name/electron-buidler | 1.0.0–1.0.2 | 2026-06-07 20:54:50 → 21:03:24 | 2026-07-27 01:30:38 | | @403name/ether-js | 1.0.0–1.0.2 | 2026-06-07 20:54:49 → 21:03:24 | 2026-07-27 01:30:47 | | @403name/fsevent | 1.0.0–1.0.2 | 2026-06-07 20:54:49 → 21:03:24 | 2026-07-27 01:30:56 |
Same-account scope publishing — all three packages published in a 9-minute window on 2026-06-07 20:54 → 21:03 UTC, then updated in lockstep to 1.0.1 (all at 20:56:51–20:56:52 UTC) and 1.0.2 (all at 21:03:24 UTC). The one-second inter-publish gap in each round is a signature of a scripted-publisher. Every package name typosquats a household-name dependency: fsevents (the macOS filesystem-events binding shipped as an optional dep in millions of Node projects), electron-builder (Electron packaging), ethers (Ethereum JavaScript SDK).
Cluster 6 — edu-npm-* "educational" postinstall family (4 packages)
| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | edu-npm-helper-alpha | 1.0.0 | 2026-06-11 07:40:15 | 2026-07-27 01:26:36 | | edu-npm-helper-beta | 1.0.0 | 2026-06-11 07:40:33 | 2026-07-27 01:26:41 | | edu-npm-dependency-chain-demo | 1.0.0–1.0.4 (5 versions) | 2026-06-11 07:54:37 → 08:23:30 | 2026-07-27 01:26:31 | | edu-npm-postinstall-demo2 | 1.0.0–1.0.3 (4 versions) | 2026-06-11 07:54:00 → 08:23:10 | 2026-07-27 01:26:46 |
All four packages published within a 43-minute window on 2026-06-11 07:40 → 08:23 UTC. GHSA-flagged as CWE-506 despite the "educational" naming — the packages exercise real postinstall / dependency-chain exec primitives and any lockfile picking them up runs the demonstration payload on install. Nobody legitimately depends on an edu-npm-* name, so any hit represents intentional installation for research or a compromised research-tool leak into production.
Cluster 7 — @wrenfield crypto-SDK typosquats (2 packages)
| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | @wrenfield/abitype | 1.2.3, 1.2.4, 1.2.6, 1.2.7 | 2026-06-21 00:55 → 2026-06-22 09:36 | 2026-07-27 01:06:23 | | @wrenfield/viem | 2.53.1–2.53.4 | 2026-06-21 00:57 → 2026-06-22 09:41 | 2026-07-27 01:06:32 |
Both packages use the exact then-current version numbers of the legitimate abitype (1.2.x series) and viem (2.53.x series) — the operator deliberately semver-aligned so that a lockfile refresh with a caret range against a mirror that resolved from a global feed would treat them as "one minor bump" from the legitimate release. viem and abitype are the core dependencies of the wagmi Ethereum React tooling ecosystem; any developer wiring up on-chain interactions is likely to touch both.
Cluster 8 — kalipto (2 packages)
| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | kalipto-runtime | 1.0.0 | 2026-06-14 05:26:45 | 2026-07-27 05:32:26 | | @kalipto/local | 1.0.0–1.0.3 | 2026-06-14 06:39 → 07:03 | 2026-07-27 05:32:56 |
No clear legitimate kalipto upstream — likely an internal-tooling brand impersonation attempt or a niche framework typosquat. Both packages published on 2026-06-14 within a 1.5-hour window; security-replaced within 30 seconds of each other on 2026-07-27.
Cluster 9 — @ceeferenderer/* dep-confusion pair (2 packages)
| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | @ceeferenderer/fe-renderer-sdk | 9.9.0, 9.9.9, 99.9.9 | 2026-03-13 01:07 → 2026-03-14 19:08 | 2026-07-27 01:04:31 | | @ceeferenderer/itg-renderer-sdk | 9.9.0, 9.9.9, 99.9.9 | 2026-03-13 01:07 → 2026-03-14 19:08 | 2026-07-27 01:04:41 |
137 days of dormancy — the oldest packages in this batch. The absurdly-inflated version numbers (9.9.0, 9.9.9, culminating in 99.9.9) are the textbook dependency-confusion signature: the attacker guesses at an internal package name at a specific organisation and publishes a version high enough that any semver-caret resolution against a public registry mirror would pull the malicious public version over the private one. Both scope members follow the same publish cadence and version-inflation pattern.
Cluster 10 — permc*server (2 packages)
| Package | Versions | Publish window (UTC) | npm security-replace (UTC) | |---|---|---|---| | permcserver | 1.0.0–1.0.4 | 2026-07-08 21:49 → 2026-07-14 14:45 | 2026-07-27 01:15:14 | | permcarmserver | 1.0.0 | 2026-07-12 06:50:10 | 2026-07-27 01:15:09 |
No clear upstream target; the -server suffix suggests server-daemon impersonation. Both packages security-replaced within 5 seconds on 2026-07-27 01:15:09 → 01:15:14 UTC, confirming npm-support handled them as a single cluster.
Singleton dep-confusion — ap3-components-ui@9.999.0
Published 2026-07-10 05:09:31 UTC as a single 9.999.0 version — a textbook dep-confusion attempt targeting an internal ap3-components-ui package name (likely a private component library at a specific organisation). Security-replaced 2026-07-27 02:37:44 UTC.
Singletons
| Package | Version(s) | Publish (UTC) | npm security-replace (UTC) | |---|---|---|---| | fluterjs | 1.0.0 | 2026-06-29 21:50:48 | 2026-07-27 05:36:35 | | jextic-eclib | 1.0.0 | 2026-06-11 19:19:01 | 2026-07-27 02:38:44 | | roblox-api-client | 1.0.0 | 2026-06-14 00:30:43 | 2026-07-27 01:27:15 | | npx-whoami-demo | 1.0.0 | 2026-06-14 12:09:07 | 2026-07-27 05:26:22 | | @ci-lifecycle-test/postinstall-ping | 1.0.0 | 2026-06-12 21:57:29 | 2026-07-27 02:40:19 | | v018-axios-cdntest | 1.0.0–1.0.3 (4 versions) | 2026-06-08 20:49 → 2026-06-09 06:18 | 2026-07-27 01:23:53 |
fluterjs typosquats Flutter (although Flutter is a Dart framework, not JS). roblox-api-client targets Roblox game-dev tooling. npx-whoami-demo and @ci-lifecycle-test/postinstall-ping present as demo / test packages but earned CWE-506 classification, so the demonstrated behaviour is malicious. v018-axios-cdntest — despite the "cdntest" naming — delivered live malware (4 versions across 10 hours on 2026-06-08 → 2026-06-09).
Registry state
All 47 packages security-replaced with 0.0.1-security sentinel tarballs. Original version tarballs are no longer resolvable on the public registry, but private registry mirrors that cached the tarballs during the publish windows (some dating back to 2026-03 for the @ceeferenderer/* pair) WILL keep serving the original versions after the public yank — any lockfile hit must be treated as actionable regardless of what the public registry currently returns.
Related tracked activity
- The same 2026-07-27 batch included 3 more packages under the
@thone33scope (@thone33/analytics-injector,@thone33/core-utils,@thone33/react-helpers) — these are catalogued in the pre-existingnpm-2026-06-28-thone33-c2-stager-clustermodule which was updated on this ingest to add@thone33/react-helpers. polymarket-stake-mathswas likewise in the batch; it is catalogued innpm-2026-07-17-polymarket-trap-clob-client-math(updated to add the trailing-s sibling of the trackedpolymarket-stake-math).- The Baileys-family cluster (Cluster 2) is a direct follow-on to the
npm-2026-07-15-ghsa-malware-sweep@sauruslord/*/zaldy-baileyssweep — same-family payload behaviour, later takedown pass catching the survivors.
Affected packages (46)
- npm
@403name/electron-buidler1.0.01.0.11.0.2 - npm
@403name/ether-js1.0.01.0.11.0.2 - npm
@403name/fsevent1.0.01.0.11.0.2 - npm
@ceeferenderer/fe-renderer-sdk9.9.09.9.999.9.9 - npm
@ceeferenderer/itg-renderer-sdk9.9.09.9.999.9.9 - npm
@ci-lifecycle-test/postinstall-ping1.0.0 - npm
@fazzcode/baileys0.1.10.1.50.1.60.1.72.0.62.4.42.5.32.5.42.5.52.5.62.5.7 - npm
@kalipto/local1.0.01.0.11.0.21.0.3 - npm
@vinnxcode/libsignal-node1.0.01.0.1 - npm
@vinnxcode/xbailsync1.0.01.0.1 - npm
@wrenfield/abitype1.2.31.2.41.2.61.2.7 - npm
@wrenfield/viem2.53.12.53.22.53.32.53.4 - npm
amanexzyra-baileys3.0.04.0.04.0.2 - npm
ap3-components-ui9.999.0 - npm
chai-log1.1.0 - npm
edu-npm-dependency-chain-demo1.0.01.0.11.0.21.0.31.0.4 - npm
edu-npm-helper-alpha1.0.0 - npm
edu-npm-helper-beta1.0.0 - npm
edu-npm-postinstall-demo21.0.01.0.11.0.21.0.3 - npm
fazzanime0.3.20.3.30.3.4 - npm
fazzgram0.1.00.1.1 - npm
fluterjs1.0.0 - npm
jextic-eclib1.0.0 - npm
kalipto-runtime1.0.0 - npm
log-taker0.0.70.0.80.0.90.1.0 - npm
log-taker10.1.0 - npm
npx-whoami-demo1.0.0 - npm
permcarmserver1.0.0 - npm
permcserver1.0.01.0.11.0.21.0.31.0.4 - npm
rainbokit0.0.8 - npm
rainbownkit0.0.8 - npm
roblox-api-client1.0.0 - npm
sixbails1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.1.01.1.11.1.2 - npm
therdweb0.0.8 - npm
thidweb0.0.8 - npm
thirdwb0.0.8 - npm
thirdwebb0.0.8 - npm
thirdwebjs0.0.8 - npm
thurdweb0.0.8 - npm
ts-escro0.0.60.0.70.0.80.0.9 - npm
ts-escrow0.0.90.1.0 - npm
txs-builder1.0.6 - npm
txs-random-lib1.0.1 - npm
txs-runner-lib1.0.1 - npm
txs-sdk-lib1.0.1 - npm
v018-axios-cdntest1.0.01.0.11.0.21.0.3
Impact
- Any host that installed any of the 47 packages listed below should be treated as fully compromised — every GHSA record uses the boilerplate CWE-506 "any computer that has this package installed or running should be considered fully compromised — rotate all secrets from a different computer" language, and no patched version exists
- Cluster 1 —
thirdweb/rainbowkitcrypto-wallet SDK typosquats (8 packages, all0.0.8, published 2026-06-19 08:19 → 09:07 UTC in a 48-minute burst):therdweb,thidweb,thirdwb,thirdwebb,thirdwebjs,thurdweb(all typosquats of the legitimatethirdwebWeb3 SDK — the operator produced every plausible one-character permutation of the target name), plusrainbokitandrainbownkit(typosquats of@rainbow-me/rainbowkit, the popular Ethereum wallet-connect React library). A crypto developer autocomplete-typingnpm install thirdweband landing on any one of six near-misses is the intended vector; the 38-day dormancy on the registry (2026-06-19 → 2026-07-27) means anyone who pulled one of these into a build has had wallet material exposed for over a month - Cluster 2 — WhatsApp-Baileys credential-scraper family (6 packages):
@fazzcode/baileys(11 versions across 2026-01-25 → 2026-06-21),sixbails(12 versions across 2026-06-19 → 2026-07-12),amanexzyra-baileys(3 versions across 2026-06-22 → 2026-06-29),@vinnxcode/libsignal-node+@vinnxcode/xbailsync(2026-07-16),fazzanime(2026-05-24),fazzgram(2026-05-28). All fit the pattern of the Xygeni-tracked Baileys-fork infostealer family (see the siblingnpm-2026-07-15-ghsa-malware-sweep@sauruslord/baileys/zaldy-baileyscluster) — malicious forks of the legitimate@whiskeysockets/baileysWhatsApp Web scraper that add credential exfil or session hijack.@fazzcode/baileysin particular has the longest exposure — six months of active publishing before 2026-07-27 takedown - Cluster 3 —
log-taker/ts-escrowsibling cluster (4 packages, published 2026-06-19 06:24 → 07:54 UTC):log-taker(0.0.7–0.1.0, 4 versions),log-taker1(0.1.0),ts-escrow(0.0.9,0.1.0),ts-escro(0.0.6–0.0.9, 4 versions). The typo pairts-escrow/ts-escromimics generic TypeScript escrow-contract tooling;log-taker/log-taker1masquerades as logging utilities. Same 90-minute publish window as Cluster 1 (thirdweb) — highly likely the same operator across both crypto-adjacent typosquat vocabularies - *Cluster 4 — `txs-
+chai-logoperator cluster** (5 packages, published 2026-06-25 → 2026-07-10):txs-builder(1.0.6),txs-runner-lib,txs-random-lib,txs-sdk-lib(all1.0.1),chai-log(1.1.0). Thetxs-names mimic transaction-processing tooling (on-chain tx builders);chai-logtyposquats thechaitest framework by suggesting a logging plugin. Cross-cluster publish-time alignment on 2026-07-10 07:03–07:25 UTC (threetxs-packages within 22 minutes) pluschai-log` on the same day at 07:09 UTC strongly implicates a single automated publisher - *Cluster 5 — `@403name/
typosquat cluster** (3 packages, all1.0.0–1.0.2, published 2026-06-07 20:54 → 21:03 UTC):@403name/fsevent(typosquat offsevents, the macOS filesystem-events binding shipped as an optional dep in millions of projects),@403name/electron-buidler(typosquat ofelectron-builder),@403name/ether-js(typosquat ofethers). Same-account scope publishing — all three packages published within a 9-minute window and updated in lockstep to1.0.1then1.0.2` - *Cluster 6 — `edu-npm-
"educational" postinstall family** (4 packages, published 2026-06-11 07:40 → 08:23 UTC):edu-npm-helper-alpha,edu-npm-helper-beta(both1.0.0),edu-npm-dependency-chain-demo(1.0.0–1.0.4, 5 versions),edu-npm-postinstall-demo2(1.0.0–1.0.3, 4 versions). GHSA-flagged as CWE-506 despite the "educational" naming — the packages exercise real postinstall / dependency-chain exec primitives and any lockfile picking them up runs the demonstration payload on install. Nobody legitimately depends on anedu-npm-*` name, so any hit represents intentional installation for research or a compromised research-tool leak into production - Cluster 7 —
@wrenfieldcrypto-SDK typosquats (2 packages, published 2026-06-21 → 2026-06-22):@wrenfield/abitype(1.2.3,1.2.4,1.2.6,1.2.7— using the exact1.2.xversion numbers of the current-line legitimateabitype),@wrenfield/viem(2.53.1–2.53.4— matching the then-currentviem2.53.xline). Both target the wagmi/viem Ethereum tooling ecosystem; the semver-alignment with real releases is deliberate so lockfile-refresh workflows resolve them as "one minor bump" from the legitimate version - Cluster 8 —
kalipto(2 packages, 2026-06-14):kalipto-runtime(1.0.0),@kalipto/local(1.0.0–1.0.3). No plausible legitimatekaliptoupstream — likely an internal-tooling-brand impersonation attempt or a niche framework typosquat - *Cluster 9 — `@ceeferenderer/
dep-confusion pair** (2 packages, published 2026-03-13 → 2026-03-14 — 4-month dormancy before 2026-07-27 takedown):@ceeferenderer/fe-renderer-sdk,@ceeferenderer/itg-renderer-sdk, both9.9.0/9.9.9/99.9.9`. The absurdly-inflated version numbers are the classic dependency-confusion signature — the attacker guesses at an internal package name and publishes a version high enough that any organisation using semver-caret resolution against a public registry would pull the malicious public version over the private one - *Cluster 10 — `permcserver
** (2 packages, published 2026-07-08 → 2026-07-14):permcserver(1.0.0–1.0.4, 5 versions),permcarmserver(1.0.0). No clear upstream target — the-server` suffix suggests server-daemon impersonation - Singleton dep-confusion —
ap3-components-ui@9.999.0(published 2026-07-10 05:09 UTC): the single9.999.0version is a textbook dep-confusion attempt — an inflated version number targeting an internalap3-components-uipackage name (likely a private component library at a specific organisation). Any org using semver-caret resolution against a public registry mirror would pull this over their internal package on the next lockfile refresh - Singletons —
fluterjs(Flutter typosquat, 2026-06-29),jextic-eclib,roblox-api-client,npx-whoami-demo,@ci-lifecycle-test/postinstall-ping,v018-axios-cdntest: mixed origins.v018-axios-cdntestin particular is worth flagging — the name suggests a test package for exercising axios via CDN, but the CWE-506 classification means it delivered live malware, not benign test content - None of the 47 packages have surviving version tarballs on the public npm registry — all replaced with
0.0.1-securitysentinel tarballs between 2026-07-27 01:02 and 05:36 UTC. Private registry mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs during the various publish windows (some dating back to 2026-03) WILL keep serving the original versions after the public yank
What to do
- 1Grep every lockfile (
package-lock.json,yarn.lock,pnpm-lock.yaml) for each name in the packages map below. Any match is a supply-chain incident: rotate every credential the build runner could reach and re-image the build host - 2Highest-priority remediation —
thirdweb/rainbowkittyposquat cluster: if any oftherdweb,thidweb,thirdwb,thirdwebb,thirdwebjs,thurdweb,rainbokit,rainbownkitappears in a lockfile, treat as a wallet-compromise event. Rotate every crypto wallet key, seed phrase, hot-wallet secret, and hardware-wallet PIN accessible from the dev host. Move funds via a clean device BEFORE attempting rotation. The 38-day exposure window means the wallet material may have been drained already — check on-chain balances first - 3*If any `@wrenfield/
package appears**: same as above — theabitype/viem` typosquats are wagmi/viem ecosystem-facing crypto-wallet targeting. Rotate wallet material, then rotate any adjacent developer credentials (npm tokens, GitHub tokens, cloud CLI tokens) - 4If any Baileys-fork package appears (
@fazzcode/baileys,sixbails,amanexzyra-baileys,@vinnxcode/xbailsync,@vinnxcode/libsignal-node,fazzanime,fazzgram): the WhatsApp session cookie / auth-state files under./auth_info_baileys/are likely already exfiltrated. Rotate the paired WhatsApp account (logout all sessions from the WhatsApp mobile app, then re-pair with fresh QR), and treat any credentials handled by the bot process as compromised - 5*If any `@403name/
package appears**: cross-check whether the intended dependency wasfsevents(mistyped as@403name/fsevent),electron-builder(mistyped as@403name/electron-buidler), orethers(mistyped as@403name/ether-js) — these are the canonical typosquats. All three versions (1.0.0,1.0.1,1.0.2`) are compromised - 6*If any `txs-
orchai-logpackage appears**: the same-day publish alignment on 2026-07-10 07:03–07:25 UTC implicates a single automated publisher; audit CI logs fornpm install` runs on that window and rotate CI-runner credentials - 7If
ap3-components-ui@9.999.0appears: this is dependency-confusion — you have an INTERNAL package namedap3-components-uithat a public-registry lookup outranked. Configure your registry client to scope-restrict private packages (.npmrcscope-to-registry mapping), then rebuild the lockfile against the private registry. Rotate any secrets that were reachable from build hosts that installed the9.999.0version - 8*If any `@ceeferenderer/
package appears**: same as above — the9.9.9/99.9.9` inflated version numbers are dep-confusion. Even though the packages were on the registry since 2026-03, the 4-month dormancy means the exposure window is longer than most; audit build-host activity from 2026-03-13 forward - 9*If any `edu-npm-` package appears**: nobody legitimately depends on these — a hit indicates either a compromised research-tool leak into production or an intentional install by a developer who typed the name manually. Investigate the human commit that added the dependency
- 10For projects using
postinstall-scripting packages, runnpm install --ignore-scriptsin CI as a defense-in-depth measure and invoke scripts only for vetted first-party packages - 11Verify none of the 47 listed packages still resolves via your private mirror — internal Artifactory / Nexus / Verdaccio instances routinely cache tarballs and will keep serving the original versions after the public yank
- 12The sibling packages
@thone33/analytics-injector,@thone33/core-utils, and@thone33/react-helperswere also in the 2026-07-27 batch — they are catalogued innpm-2026-06-28-thone33-c2-stager-cluster;polymarket-stake-mathswas likewise in the batch and is catalogued innpm-2026-07-17-polymarket-trap-clob-client-math. Both are cross-referenced from this module rather than duplicated
References
- GitHubGitHub Advisory Database — recent npm malware advisoriesgithub.com
- GitHubGHSA-8jr3-m3cj-m436 — thirdwebjs malware advisorygithub.com
- GitHubGHSA-56vv-8v7m-r49g — rainbokit malware advisorygithub.com
- GitHubGHSA-vj5m-3jrw-83gx — rainbownkit malware advisorygithub.com
- GitHubGHSA-g2vx-7x66-f2wv — therdweb malware advisorygithub.com
- GitHubGHSA-ccmq-q5j8-hvxc — thirdwb malware advisorygithub.com
- GitHubGHSA-3vx6-4gr6-qj63 — thidweb malware advisorygithub.com
- GitHubGHSA-46px-g2r9-8vcr — thirdwebb malware advisorygithub.com
- GitHubGHSA-vx4c-33rj-4xv8 — thurdweb malware advisorygithub.com
- GitHubGHSA-6f83-g2m3-3wwr — @wrenfield/abitype malware advisorygithub.com
- GitHubGHSA-pm4g-83cj-7858 — @wrenfield/viem malware advisorygithub.com
- GitHubGHSA-wqqq-qm88-5433 — @fazzcode/baileys malware advisorygithub.com
- GitHubGHSA-8cvc-378h-fwqf — sixbails malware advisorygithub.com
- GitHubGHSA-mwwh-7r57-h6v9 — amanexzyra-baileys malware advisorygithub.com
- GitHubGHSA-v9rv-pgqp-436h — @vinnxcode/libsignal-node malware advisorygithub.com
- GitHubGHSA-fgwc-g3q5-794p — @vinnxcode/xbailsync malware advisorygithub.com
- GitHubGHSA-r3jh-34p6-m7xp — fazzanime malware advisorygithub.com
- GitHubGHSA-vjhp-hr8c-42m8 — fazzgram malware advisorygithub.com
- GitHubGHSA-x8v5-5q93-844w — log-taker malware advisorygithub.com
- GitHubGHSA-35q5-q365-j23w — log-taker1 malware advisorygithub.com
- GitHubGHSA-fjgh-3fjv-prm3 — ts-escrow malware advisorygithub.com
- GitHubGHSA-5hm9-jj3m-6q76 — ts-escro malware advisorygithub.com
- GitHubGHSA-5g95-w82p-69v9 — txs-builder malware advisorygithub.com
- GitHubGHSA-65pq-67vr-g3jp — txs-runner-lib malware advisorygithub.com
- GitHubGHSA-c2fc-52mv-g5v6 — txs-random-lib malware advisorygithub.com
- GitHubGHSA-fgmc-rrjh-9m33 — txs-sdk-lib malware advisorygithub.com
- GitHubGHSA-2534-xr99-f4wh — chai-log malware advisorygithub.com
- GitHubGHSA-hp95-92q5-xfvc — @403name/fsevent malware advisorygithub.com
- GitHubGHSA-h23r-x34f-p95m — @403name/electron-buidler malware advisorygithub.com
- GitHubGHSA-qgxg-2j6w-jmpx — @403name/ether-js malware advisorygithub.com
- GitHubGHSA-mw7m-6vvq-q69p — @ceeferenderer/fe-renderer-sdk malware advisorygithub.com
- GitHubGHSA-3v4h-w4g3-h6r2 — @ceeferenderer/itg-renderer-sdk malware advisorygithub.com
- GitHubGHSA-qhgr-v9vh-3784 — ap3-components-ui malware advisorygithub.com
- GitHubGHSA-gj4r-435f-67cr — fluterjs malware advisorygithub.com
- GitHubGHSA-g6f3-9j93-879j — kalipto-runtime malware advisorygithub.com
- GitHubGHSA-653g-2cfx-6gpc — @kalipto/local malware advisorygithub.com
- GitHubGHSA-9499-pgrg-v7w7 — permcarmserver malware advisorygithub.com
- GitHubGHSA-vjr2-cx8x-3q2x — permcserver malware advisorygithub.com
- GitHubGHSA-hmpp-mfgc-mq8p — roblox-api-client malware advisorygithub.com
- GitHubGHSA-3mmq-8798-7f4v — npx-whoami-demo malware advisorygithub.com
- GitHubGHSA-q86v-7cxj-6979 — @ci-lifecycle-test/postinstall-ping malware advisorygithub.com
- GitHubGHSA-cw6g-r53q-23c2 — v018-axios-cdntest malware advisorygithub.com
- GitHubGHSA-fvh5-fhfx-3whm — jextic-eclib malware advisorygithub.com
- GitHubGHSA-cqgx-r84j-px55 — edu-npm-dependency-chain-demo malware advisorygithub.com
- GitHubGHSA-mm62-vp6v-vqq2 — edu-npm-helper-beta malware advisorygithub.com
- GitHubGHSA-jhpp-p77r-39q6 — edu-npm-helper-alpha malware advisorygithub.com
- GitHubGHSA-gqxv-6fpm-5xwx — edu-npm-postinstall-demo2 malware advisorygithub.com