# GitHub Advisory npm CWE-506 sweep - 47-package overnight batch (8-package `thirdweb` / `rainbowkit` crypto-wallet typosquat cluster, 6-package baileys/WhatsApp-scraper `fazz*` + `@vinnxcode` + `sixbails` family, 4-package `log-taker` / `ts-escrow` sibling cluster, 5-package `txs-*` + `chai-log` operator cluster, 3-package `@403name/*` typosquat cluster, 4-package `edu-npm-*` "educational" postinstall family, `@wrenfield/abitype` + `@wrenfield/viem` crypto-SDK typosquats, `@kalipto/local` + `kalipto-runtime`, `@ceeferenderer/*` dep-confusion pair, `ap3-components-ui` v9.999.0 dep-confusion, `permcserver` / `permcarmserver`, plus singletons) retired 2026-07-27 01:02–05:36 UTC

> On 2026-07-27 01:02 → 05:36 UTC GitHub retired **47 npm CWE-506 malware advisories** in a single overnight batch. Twelve clusters spanning crypto-wallet typosquats (`thirdweb` / `rainbowkit` / `@wrenfield/viem`), WhatsApp-Baileys scrapers (`fazz*`, `@vinnxcode`, `sixbails`, `amanexzyra-baileys`), dependency-confusion (`ap3-components-ui@9.999.0`, `@ceeferenderer/*`), postinstall droppers (`txs-*`, `chai-log`, `edu-npm-*`, `@403name/*`), plus singletons. All 47 packages security-replaced with `0.0.1-security` sentinel tarballs.

- Published: 2026-07-27
- Severity: high
- Kind: Advisory sweep - A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
- Ecosystems: npm
- Scope: 46 packages, 114 compromised versions
- Tags: typosquat, crypto-wallet-drain, credential-theft, dependency-confusion, infostealer
- Also known as: 2026-07-27 GHSA npm overnight sweep, thirdweb rainbowkit typosquat cluster, fazz/vinnxcode baileys family follow-on
- Detected by: GitHub Advisory Database, npm Security
- Incident ID: npm-2026-07-27-ghsa-malware-sweep

## Affected packages (46)

Only the exact versions listed were named by the source advisories. Other versions are not implicated.

| Package | Ecosystem | Compromised versions |
|---|---|---|
| [@403name/electron-buidler](https://dependencywatch.io/package/npm/@403name/electron-buidler) | npm | 1.0.0, 1.0.1, 1.0.2 |
| [@403name/ether-js](https://dependencywatch.io/package/npm/@403name/ether-js) | npm | 1.0.0, 1.0.1, 1.0.2 |
| [@403name/fsevent](https://dependencywatch.io/package/npm/@403name/fsevent) | npm | 1.0.0, 1.0.1, 1.0.2 |
| [@ceeferenderer/fe-renderer-sdk](https://dependencywatch.io/package/npm/@ceeferenderer/fe-renderer-sdk) | npm | 9.9.0, 9.9.9, 99.9.9 |
| [@ceeferenderer/itg-renderer-sdk](https://dependencywatch.io/package/npm/@ceeferenderer/itg-renderer-sdk) | npm | 9.9.0, 9.9.9, 99.9.9 |
| [@ci-lifecycle-test/postinstall-ping](https://dependencywatch.io/package/npm/@ci-lifecycle-test/postinstall-ping) | npm | 1.0.0 |
| [@fazzcode/baileys](https://dependencywatch.io/package/npm/@fazzcode/baileys) | npm | 0.1.1, 0.1.5, 0.1.6, 0.1.7, 2.0.6, 2.4.4, 2.5.3, 2.5.4, 2.5.5, 2.5.6, 2.5.7 |
| [@kalipto/local](https://dependencywatch.io/package/npm/@kalipto/local) | npm | 1.0.0, 1.0.1, 1.0.2, 1.0.3 |
| [@vinnxcode/libsignal-node](https://dependencywatch.io/package/npm/@vinnxcode/libsignal-node) | npm | 1.0.0, 1.0.1 |
| [@vinnxcode/xbailsync](https://dependencywatch.io/package/npm/@vinnxcode/xbailsync) | npm | 1.0.0, 1.0.1 |
| [@wrenfield/abitype](https://dependencywatch.io/package/npm/@wrenfield/abitype) | npm | 1.2.3, 1.2.4, 1.2.6, 1.2.7 |
| [@wrenfield/viem](https://dependencywatch.io/package/npm/@wrenfield/viem) | npm | 2.53.1, 2.53.2, 2.53.3, 2.53.4 |
| [amanexzyra-baileys](https://dependencywatch.io/package/npm/amanexzyra-baileys) | npm | 3.0.0, 4.0.0, 4.0.2 |
| [ap3-components-ui](https://dependencywatch.io/package/npm/ap3-components-ui) | npm | 9.999.0 |
| [chai-log](https://dependencywatch.io/package/npm/chai-log) | npm | 1.1.0 |
| [edu-npm-dependency-chain-demo](https://dependencywatch.io/package/npm/edu-npm-dependency-chain-demo) | npm | 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4 |
| [edu-npm-helper-alpha](https://dependencywatch.io/package/npm/edu-npm-helper-alpha) | npm | 1.0.0 |
| [edu-npm-helper-beta](https://dependencywatch.io/package/npm/edu-npm-helper-beta) | npm | 1.0.0 |
| [edu-npm-postinstall-demo2](https://dependencywatch.io/package/npm/edu-npm-postinstall-demo2) | npm | 1.0.0, 1.0.1, 1.0.2, 1.0.3 |
| [fazzanime](https://dependencywatch.io/package/npm/fazzanime) | npm | 0.3.2, 0.3.3, 0.3.4 |
| [fazzgram](https://dependencywatch.io/package/npm/fazzgram) | npm | 0.1.0, 0.1.1 |
| [fluterjs](https://dependencywatch.io/package/npm/fluterjs) | npm | 1.0.0 |
| [jextic-eclib](https://dependencywatch.io/package/npm/jextic-eclib) | npm | 1.0.0 |
| [kalipto-runtime](https://dependencywatch.io/package/npm/kalipto-runtime) | npm | 1.0.0 |
| [log-taker](https://dependencywatch.io/package/npm/log-taker) | npm | 0.0.7, 0.0.8, 0.0.9, 0.1.0 |
| [log-taker1](https://dependencywatch.io/package/npm/log-taker1) | npm | 0.1.0 |
| [npx-whoami-demo](https://dependencywatch.io/package/npm/npx-whoami-demo) | npm | 1.0.0 |
| [permcarmserver](https://dependencywatch.io/package/npm/permcarmserver) | npm | 1.0.0 |
| [permcserver](https://dependencywatch.io/package/npm/permcserver) | npm | 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4 |
| [rainbokit](https://dependencywatch.io/package/npm/rainbokit) | npm | 0.0.8 |
| [rainbownkit](https://dependencywatch.io/package/npm/rainbownkit) | npm | 0.0.8 |
| [roblox-api-client](https://dependencywatch.io/package/npm/roblox-api-client) | npm | 1.0.0 |
| [sixbails](https://dependencywatch.io/package/npm/sixbails) | npm | 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.1.0, 1.1.1, 1.1.2 |
| [therdweb](https://dependencywatch.io/package/npm/therdweb) | npm | 0.0.8 |
| [thidweb](https://dependencywatch.io/package/npm/thidweb) | npm | 0.0.8 |
| [thirdwb](https://dependencywatch.io/package/npm/thirdwb) | npm | 0.0.8 |
| [thirdwebb](https://dependencywatch.io/package/npm/thirdwebb) | npm | 0.0.8 |
| [thirdwebjs](https://dependencywatch.io/package/npm/thirdwebjs) | npm | 0.0.8 |
| [thurdweb](https://dependencywatch.io/package/npm/thurdweb) | npm | 0.0.8 |
| [ts-escro](https://dependencywatch.io/package/npm/ts-escro) | npm | 0.0.6, 0.0.7, 0.0.8, 0.0.9 |
| [ts-escrow](https://dependencywatch.io/package/npm/ts-escrow) | npm | 0.0.9, 0.1.0 |
| [txs-builder](https://dependencywatch.io/package/npm/txs-builder) | npm | 1.0.6 |
| [txs-random-lib](https://dependencywatch.io/package/npm/txs-random-lib) | npm | 1.0.1 |
| [txs-runner-lib](https://dependencywatch.io/package/npm/txs-runner-lib) | npm | 1.0.1 |
| [txs-sdk-lib](https://dependencywatch.io/package/npm/txs-sdk-lib) | npm | 1.0.1 |
| [v018-axios-cdntest](https://dependencywatch.io/package/npm/v018-axios-cdntest) | npm | 1.0.0, 1.0.1, 1.0.2, 1.0.3 |

## What happened

On 2026-07-27 between 01:02 and 05:36 UTC, GitHub's Advisory Database published **50 new CWE-506 (Embedded Malicious Code) advisories** against npm packages in a single overnight batch. This module catalogues 47 of the 50 (the remaining 3 - `@thone33/analytics-injector`, `@thone33/core-utils`, `@thone33/react-helpers` - are absorbed into the pre-existing `npm-2026-06-28-thone33-c2-stager-cluster` record; `polymarket-stake-maths` is absorbed into `npm-2026-07-17-polymarket-trap-clob-client-math`). All 47 records use the standard CWE-506 boilerplate "any computer that has this package installed or running should be considered fully compromised - rotate all secrets from a different computer" and were security-replaced by the npm-support team on 2026-07-27 between 01:02:28 UTC (`fazzgram`) and 05:36:35 UTC (`fluterjs`).

Unlike a typical daily sweep, this batch spans **~19 weeks of prior publisher activity** - from `@ceeferenderer/fe-renderer-sdk@9.9.0` (published 2026-03-13, 137 days of dormancy) through `ap3-components-ui@9.999.0` (published 2026-07-10, 17 days of dormancy) to fresh drops like the `@vinnxcode` scope (published 2026-07-16, 11 days of dormancy). The batch shape strongly suggests a coordinated take-down operation by npm-security against multiple long-running clusters, likely triggered by a signal upstream (Amazon Inspector, OpenSSF Package Analysis, or a security-vendor tip) rather than a fresh attack burst.

## Cluster 1 - `thirdweb` / `rainbowkit` crypto-wallet SDK typosquats (8 packages)

| Package | Version | Publish (UTC) | npm security-replace (UTC) |
|---|---|---|---|
| `rainbokit` | `0.0.8` | 2026-06-19 08:19:25 | 2026-07-27 01:16:24 |
| `rainbownkit` | `0.0.8` | 2026-06-19 08:19:42 | 2026-07-27 01:16:29 |
| `therdweb` | `0.0.8` | 2026-06-19 09:06:29 | 2026-07-27 01:16:34 |
| `thidweb` | `0.0.8` | 2026-06-19 09:06:45 | 2026-07-27 01:16:39 |
| `thirdwb` | `0.0.8` | 2026-06-19 09:06:16 | 2026-07-27 01:16:44 |
| `thirdwebb` | `0.0.8` | 2026-06-19 09:05:28 | 2026-07-27 01:16:49 |
| `thirdwebjs` | `0.0.8` | 2026-06-19 09:05:56 | 2026-07-27 01:16:54 |
| `thurdweb` | `0.0.8` | 2026-06-19 09:07:07 | 2026-07-27 01:16:59 |

All eight packages published within a 48-minute window on 2026-06-19 (8:19 → 9:07 UTC) using the same `0.0.8` version tag (deliberately chosen to appear as a "patch" of an existing legitimate package). The legitimate `thirdweb` npm package is a Web3 SDK with millions of weekly downloads; `@rainbow-me/rainbowkit` is the most popular Ethereum wallet-connect React library. The operator generated every plausible one-character permutation of the target names - anyone autocomplete-typing `thirdweb` in `package.json` has six near-misses to hit. All eight packages security-replaced within a 35-second window on 2026-07-27 01:16:24 → 01:16:59 UTC, confirming npm-security handled them as a single incident.

## Cluster 2 - WhatsApp-Baileys credential-scraper family (6 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) |
|---|---|---|---|
| `@fazzcode/baileys` | 11 versions (`0.1.1` → `2.5.7`) | 2026-01-25 → 2026-06-21 | 2026-07-27 01:02:39 |
| `sixbails` | 12 versions (`1.0.0` → `1.1.2`) | 2026-06-19 → 2026-07-12 | 2026-07-27 01:08:46 |
| `amanexzyra-baileys` | 3 versions (`3.0.0`, `4.0.0`, `4.0.2`) | 2026-06-22 → 2026-06-29 | 2026-07-27 01:03:24 |
| `@vinnxcode/libsignal-node` | 2 versions (`1.0.0`, `1.0.1`) | 2026-07-16 09:38 → 10:05 | 2026-07-27 01:08:56 |
| `@vinnxcode/xbailsync` | 2 versions (`1.0.0`, `1.0.1`) | 2026-07-16 10:10 → 10:25 | 2026-07-27 01:09:05 |
| `fazzanime` | 3 versions (`0.3.2`–`0.3.4`) | 2026-05-24 | 2026-07-27 01:02:28 |
| `fazzgram` | 2 versions (`0.1.0`, `0.1.1`) | 2026-05-28 | 2026-07-27 01:02:43 |

All six packages fit the profile of the malicious-Baileys-fork family previously documented by Xygeni ("Malicious npm Package in Baileys Fork") and Koi Security ("NPM Package With 56K Downloads Caught Stealing WhatsApp Messages"). The legitimate `@whiskeysockets/baileys` is a WhatsApp Web scraper library; malicious forks add code that reads the `./auth_info_baileys/` session-state files on `activate()` and exfiltrates them to a C2. `@fazzcode/baileys` has by far the longest publish history (six months, 11 versions from 2026-01-25) - likely a legitimate account that was compromised, or a long-play trojan-horse account that seeded benign releases before injecting the payload.

The sibling `npm-2026-07-15-ghsa-malware-sweep` module catalogues the same-family `@sauruslord/baileys` / `zaldy-baileys` / `sauruslord-baileys` cluster taken down 2026-07-15. This 2026-07-27 batch appears to be the follow-up sweep catching the survivors that were missed in the first pass.

## Cluster 3 - `log-taker` / `ts-escrow` sibling cluster (4 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) |
|---|---|---|---|
| `log-taker` | 4 versions (`0.0.7`–`0.1.0`) | 2026-06-19 06:24 → 07:54 | 2026-07-27 01:16:19 |
| `log-taker1` | `0.1.0` | 2026-06-19 21:14:34 | 2026-07-27 01:17:14 |
| `ts-escrow` | 2 versions (`0.0.9`, `0.1.0`) | 2026-06-19 21:10 → 21:16 | 2026-07-27 01:17:24 |
| `ts-escro` | 4 versions (`0.0.6`–`0.0.9`) | 2026-06-19 06:25 → 07:51 | 2026-07-27 01:17:05 |

Same 2026-06-19 publish date as Cluster 1 - the `log-taker`/`ts-escro` pair at 06:24/06:25 UTC and the follow-on `log-taker1`/`ts-escrow` pair at 21:14/21:10 UTC. The typo pair `ts-escrow`/`ts-escro` is a canonical single-character-off typosquat; the `log-taker`/`log-taker1` pair uses a numeric suffix (a signature of a re-drop after the first name attracted flagging). Same-day publishing plus same-day take-down clustering with the thirdweb batch on 2026-07-27 01:16 UTC (all four packages security-replaced within 65 seconds of the thirdweb cluster) suggests operator overlap.

## Cluster 4 - `txs-*` + `chai-log` operator cluster (5 packages)

| Package | Versions | Publish (UTC) | npm security-replace (UTC) |
|---|---|---|---|
| `txs-builder` | `1.0.6` | 2026-06-25 08:51:27 | 2026-07-27 01:22:05 |
| `txs-sdk-lib` | `1.0.1` | 2026-07-10 07:25:25 | 2026-07-27 01:19:39 |
| `txs-random-lib` | `1.0.1` | 2026-07-10 07:16:58 | 2026-07-27 01:20:19 |
| `txs-runner-lib` | `1.0.1` | 2026-07-10 07:03:57 | 2026-07-27 01:21:07 |
| `chai-log` | `1.1.0` | 2026-07-10 07:09:33 | 2026-07-27 01:18:04 |

The three `txs-*-lib` packages plus `chai-log` all published within a 22-minute window on 2026-07-10 07:03–07:25 UTC - a signature of an automated same-account publishing script. `txs-builder@1.0.6` was published 15 days earlier by (likely) the same operator as a first-drop test. The `txs-*` naming mimics transaction-processing tooling (Ethereum tx builders, transaction runners); `chai-log` typosquats the Chai test framework as a "logging plugin". All five security-replaced within 4 minutes on 2026-07-27 01:18–01:22 UTC.

## Cluster 5 - `@403name/*` typosquat cluster (3 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) |
|---|---|---|---|
| `@403name/electron-buidler` | `1.0.0`–`1.0.2` | 2026-06-07 20:54:50 → 21:03:24 | 2026-07-27 01:30:38 |
| `@403name/ether-js` | `1.0.0`–`1.0.2` | 2026-06-07 20:54:49 → 21:03:24 | 2026-07-27 01:30:47 |
| `@403name/fsevent` | `1.0.0`–`1.0.2` | 2026-06-07 20:54:49 → 21:03:24 | 2026-07-27 01:30:56 |

Same-account scope publishing - all three packages published in a 9-minute window on 2026-06-07 20:54 → 21:03 UTC, then updated in lockstep to `1.0.1` (all at 20:56:51–20:56:52 UTC) and `1.0.2` (all at 21:03:24 UTC). The one-second inter-publish gap in each round is a signature of a scripted-publisher. Every package name typosquats a household-name dependency: `fsevents` (the macOS filesystem-events binding shipped as an optional dep in millions of Node projects), `electron-builder` (Electron packaging), `ethers` (Ethereum JavaScript SDK).

## Cluster 6 - `edu-npm-*` "educational" postinstall family (4 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) |
|---|---|---|---|
| `edu-npm-helper-alpha` | `1.0.0` | 2026-06-11 07:40:15 | 2026-07-27 01:26:36 |
| `edu-npm-helper-beta` | `1.0.0` | 2026-06-11 07:40:33 | 2026-07-27 01:26:41 |
| `edu-npm-dependency-chain-demo` | `1.0.0`–`1.0.4` (5 versions) | 2026-06-11 07:54:37 → 08:23:30 | 2026-07-27 01:26:31 |
| `edu-npm-postinstall-demo2` | `1.0.0`–`1.0.3` (4 versions) | 2026-06-11 07:54:00 → 08:23:10 | 2026-07-27 01:26:46 |

All four packages published within a 43-minute window on 2026-06-11 07:40 → 08:23 UTC. GHSA-flagged as CWE-506 despite the "educational" naming - the packages exercise real postinstall / dependency-chain exec primitives and any lockfile picking them up runs the demonstration payload on install. Nobody legitimately depends on an `edu-npm-*` name, so any hit represents intentional installation for research or a compromised research-tool leak into production.

## Cluster 7 - `@wrenfield` crypto-SDK typosquats (2 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) |
|---|---|---|---|
| `@wrenfield/abitype` | `1.2.3`, `1.2.4`, `1.2.6`, `1.2.7` | 2026-06-21 00:55 → 2026-06-22 09:36 | 2026-07-27 01:06:23 |
| `@wrenfield/viem` | `2.53.1`–`2.53.4` | 2026-06-21 00:57 → 2026-06-22 09:41 | 2026-07-27 01:06:32 |

Both packages use the exact then-current version numbers of the legitimate `abitype` (`1.2.x` series) and `viem` (`2.53.x` series) - the operator deliberately semver-aligned so that a lockfile refresh with a caret range against a mirror that resolved from a global feed would treat them as "one minor bump" from the legitimate release. viem and abitype are the core dependencies of the wagmi Ethereum React tooling ecosystem; any developer wiring up on-chain interactions is likely to touch both.

## Cluster 8 - `kalipto` (2 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) |
|---|---|---|---|
| `kalipto-runtime` | `1.0.0` | 2026-06-14 05:26:45 | 2026-07-27 05:32:26 |
| `@kalipto/local` | `1.0.0`–`1.0.3` | 2026-06-14 06:39 → 07:03 | 2026-07-27 05:32:56 |

No clear legitimate `kalipto` upstream - likely an internal-tooling brand impersonation attempt or a niche framework typosquat. Both packages published on 2026-06-14 within a 1.5-hour window; security-replaced within 30 seconds of each other on 2026-07-27.

## Cluster 9 - `@ceeferenderer/*` dep-confusion pair (2 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) |
|---|---|---|---|
| `@ceeferenderer/fe-renderer-sdk` | `9.9.0`, `9.9.9`, `99.9.9` | 2026-03-13 01:07 → 2026-03-14 19:08 | 2026-07-27 01:04:31 |
| `@ceeferenderer/itg-renderer-sdk` | `9.9.0`, `9.9.9`, `99.9.9` | 2026-03-13 01:07 → 2026-03-14 19:08 | 2026-07-27 01:04:41 |

**137 days of dormancy** - the oldest packages in this batch. The absurdly-inflated version numbers (`9.9.0`, `9.9.9`, culminating in `99.9.9`) are the textbook dependency-confusion signature: the attacker guesses at an internal package name at a specific organisation and publishes a version high enough that any semver-caret resolution against a public registry mirror would pull the malicious public version over the private one. Both scope members follow the same publish cadence and version-inflation pattern.

## Cluster 10 - `permc*server` (2 packages)

| Package | Versions | Publish window (UTC) | npm security-replace (UTC) |
|---|---|---|---|
| `permcserver` | `1.0.0`–`1.0.4` | 2026-07-08 21:49 → 2026-07-14 14:45 | 2026-07-27 01:15:14 |
| `permcarmserver` | `1.0.0` | 2026-07-12 06:50:10 | 2026-07-27 01:15:09 |

No clear upstream target; the `-server` suffix suggests server-daemon impersonation. Both packages security-replaced within 5 seconds on 2026-07-27 01:15:09 → 01:15:14 UTC, confirming npm-support handled them as a single cluster.

## Singleton dep-confusion - `ap3-components-ui@9.999.0`

Published 2026-07-10 05:09:31 UTC as a single `9.999.0` version - a textbook dep-confusion attempt targeting an internal `ap3-components-ui` package name (likely a private component library at a specific organisation). Security-replaced 2026-07-27 02:37:44 UTC.

## Singletons

| Package | Version(s) | Publish (UTC) | npm security-replace (UTC) |
|---|---|---|---|
| `fluterjs` | `1.0.0` | 2026-06-29 21:50:48 | 2026-07-27 05:36:35 |
| `jextic-eclib` | `1.0.0` | 2026-06-11 19:19:01 | 2026-07-27 02:38:44 |
| `roblox-api-client` | `1.0.0` | 2026-06-14 00:30:43 | 2026-07-27 01:27:15 |
| `npx-whoami-demo` | `1.0.0` | 2026-06-14 12:09:07 | 2026-07-27 05:26:22 |
| `@ci-lifecycle-test/postinstall-ping` | `1.0.0` | 2026-06-12 21:57:29 | 2026-07-27 02:40:19 |
| `v018-axios-cdntest` | `1.0.0`–`1.0.3` (4 versions) | 2026-06-08 20:49 → 2026-06-09 06:18 | 2026-07-27 01:23:53 |

`fluterjs` typosquats Flutter (although Flutter is a Dart framework, not JS). `roblox-api-client` targets Roblox game-dev tooling. `npx-whoami-demo` and `@ci-lifecycle-test/postinstall-ping` present as demo / test packages but earned CWE-506 classification, so the demonstrated behaviour is malicious. `v018-axios-cdntest` - despite the "cdntest" naming - delivered live malware (4 versions across 10 hours on 2026-06-08 → 2026-06-09).

## Registry state

All 47 packages security-replaced with `0.0.1-security` sentinel tarballs. Original version tarballs are no longer resolvable on the public registry, but private registry mirrors that cached the tarballs during the publish windows (some dating back to 2026-03 for the `@ceeferenderer/*` pair) WILL keep serving the original versions after the public yank - any lockfile hit must be treated as actionable regardless of what the public registry currently returns.

## Related tracked activity

- The same 2026-07-27 batch included 3 more packages under the `@thone33` scope (`@thone33/analytics-injector`, `@thone33/core-utils`, `@thone33/react-helpers`) - these are catalogued in the pre-existing `npm-2026-06-28-thone33-c2-stager-cluster` module which was updated on this ingest to add `@thone33/react-helpers`.
- `polymarket-stake-maths` was likewise in the batch; it is catalogued in `npm-2026-07-17-polymarket-trap-clob-client-math` (updated to add the trailing-s sibling of the tracked `polymarket-stake-math`).
- The Baileys-family cluster (Cluster 2) is a direct follow-on to the `npm-2026-07-15-ghsa-malware-sweep` `@sauruslord/*` / `zaldy-baileys` sweep - same-family payload behaviour, later takedown pass catching the survivors.

## Impact

- Any host that installed any of the 47 packages listed below should be treated as fully compromised - every GHSA record uses the boilerplate CWE-506 "any computer that has this package installed or running should be considered fully compromised - rotate all secrets from a different computer" language, and no patched version exists
- **Cluster 1 - `thirdweb` / `rainbowkit` crypto-wallet SDK typosquats** (8 packages, all `0.0.8`, published 2026-06-19 08:19 → 09:07 UTC in a 48-minute burst): `therdweb`, `thidweb`, `thirdwb`, `thirdwebb`, `thirdwebjs`, `thurdweb` (all typosquats of the legitimate `thirdweb` Web3 SDK - the operator produced every plausible one-character permutation of the target name), plus `rainbokit` and `rainbownkit` (typosquats of `@rainbow-me/rainbowkit`, the popular Ethereum wallet-connect React library). A crypto developer autocomplete-typing `npm install thirdweb` and landing on any one of six near-misses is the intended vector; the 38-day dormancy on the registry (2026-06-19 → 2026-07-27) means anyone who pulled one of these into a build has had wallet material exposed for over a month
- **Cluster 2 - WhatsApp-Baileys credential-scraper family** (6 packages): `@fazzcode/baileys` (11 versions across 2026-01-25 → 2026-06-21), `sixbails` (12 versions across 2026-06-19 → 2026-07-12), `amanexzyra-baileys` (3 versions across 2026-06-22 → 2026-06-29), `@vinnxcode/libsignal-node` + `@vinnxcode/xbailsync` (2026-07-16), `fazzanime` (2026-05-24), `fazzgram` (2026-05-28). All fit the pattern of the Xygeni-tracked Baileys-fork infostealer family (see the sibling `npm-2026-07-15-ghsa-malware-sweep` `@sauruslord/baileys` / `zaldy-baileys` cluster) - malicious forks of the legitimate `@whiskeysockets/baileys` WhatsApp Web scraper that add credential exfil or session hijack. `@fazzcode/baileys` in particular has the longest exposure - six months of active publishing before 2026-07-27 takedown
- **Cluster 3 - `log-taker` / `ts-escrow` sibling cluster** (4 packages, published 2026-06-19 06:24 → 07:54 UTC): `log-taker` (`0.0.7`–`0.1.0`, 4 versions), `log-taker1` (`0.1.0`), `ts-escrow` (`0.0.9`, `0.1.0`), `ts-escro` (`0.0.6`–`0.0.9`, 4 versions). The typo pair `ts-escrow`/`ts-escro` mimics generic TypeScript escrow-contract tooling; `log-taker`/`log-taker1` masquerades as logging utilities. Same 90-minute publish window as Cluster 1 (thirdweb) - highly likely the same operator across both crypto-adjacent typosquat vocabularies
- **Cluster 4 - `txs-*` + `chai-log` operator cluster** (5 packages, published 2026-06-25 → 2026-07-10): `txs-builder` (`1.0.6`), `txs-runner-lib`, `txs-random-lib`, `txs-sdk-lib` (all `1.0.1`), `chai-log` (`1.1.0`). The `txs-*` names mimic transaction-processing tooling (on-chain tx builders); `chai-log` typosquats the `chai` test framework by suggesting a logging plugin. Cross-cluster publish-time alignment on 2026-07-10 07:03–07:25 UTC (three `txs-*` packages within 22 minutes) plus `chai-log` on the same day at 07:09 UTC strongly implicates a single automated publisher
- **Cluster 5 - `@403name/*` typosquat cluster** (3 packages, all `1.0.0`–`1.0.2`, published 2026-06-07 20:54 → 21:03 UTC): `@403name/fsevent` (typosquat of `fsevents`, the macOS filesystem-events binding shipped as an optional dep in millions of projects), `@403name/electron-buidler` (typosquat of `electron-builder`), `@403name/ether-js` (typosquat of `ethers`). Same-account scope publishing - all three packages published within a 9-minute window and updated in lockstep to `1.0.1` then `1.0.2`
- **Cluster 6 - `edu-npm-*` "educational" postinstall family** (4 packages, published 2026-06-11 07:40 → 08:23 UTC): `edu-npm-helper-alpha`, `edu-npm-helper-beta` (both `1.0.0`), `edu-npm-dependency-chain-demo` (`1.0.0`–`1.0.4`, 5 versions), `edu-npm-postinstall-demo2` (`1.0.0`–`1.0.3`, 4 versions). GHSA-flagged as CWE-506 despite the "educational" naming - the packages exercise real postinstall / dependency-chain exec primitives and any lockfile picking them up runs the demonstration payload on install. Nobody legitimately depends on an `edu-npm-*` name, so any hit represents intentional installation for research or a compromised research-tool leak into production
- **Cluster 7 - `@wrenfield` crypto-SDK typosquats** (2 packages, published 2026-06-21 → 2026-06-22): `@wrenfield/abitype` (`1.2.3`, `1.2.4`, `1.2.6`, `1.2.7` - using the exact `1.2.x` version numbers of the current-line legitimate `abitype`), `@wrenfield/viem` (`2.53.1`–`2.53.4` - matching the then-current `viem` `2.53.x` line). Both target the wagmi/viem Ethereum tooling ecosystem; the semver-alignment with real releases is deliberate so lockfile-refresh workflows resolve them as "one minor bump" from the legitimate version
- **Cluster 8 - `kalipto` (2 packages, 2026-06-14)**: `kalipto-runtime` (`1.0.0`), `@kalipto/local` (`1.0.0`–`1.0.3`). No plausible legitimate `kalipto` upstream - likely an internal-tooling-brand impersonation attempt or a niche framework typosquat
- **Cluster 9 - `@ceeferenderer/*` dep-confusion pair** (2 packages, published 2026-03-13 → 2026-03-14 - 4-month dormancy before 2026-07-27 takedown): `@ceeferenderer/fe-renderer-sdk`, `@ceeferenderer/itg-renderer-sdk`, both `9.9.0` / `9.9.9` / `99.9.9`. The absurdly-inflated version numbers are the classic dependency-confusion signature - the attacker guesses at an internal package name and publishes a version high enough that any organisation using semver-caret resolution against a public registry would pull the malicious public version over the private one
- **Cluster 10 - `permc*server`** (2 packages, published 2026-07-08 → 2026-07-14): `permcserver` (`1.0.0`–`1.0.4`, 5 versions), `permcarmserver` (`1.0.0`). No clear upstream target - the `-server` suffix suggests server-daemon impersonation
- **Singleton dep-confusion - `ap3-components-ui@9.999.0`** (published 2026-07-10 05:09 UTC): the single `9.999.0` version is a textbook dep-confusion attempt - an inflated version number targeting an internal `ap3-components-ui` package name (likely a private component library at a specific organisation). Any org using semver-caret resolution against a public registry mirror would pull this over their internal package on the next lockfile refresh
- **Singletons** - `fluterjs` (Flutter typosquat, 2026-06-29), `jextic-eclib`, `roblox-api-client`, `npx-whoami-demo`, `@ci-lifecycle-test/postinstall-ping`, `v018-axios-cdntest`: mixed origins. `v018-axios-cdntest` in particular is worth flagging - the name suggests a test package for exercising axios via CDN, but the CWE-506 classification means it delivered live malware, not benign test content
- None of the 47 packages have surviving version tarballs on the public npm registry - all replaced with `0.0.1-security` sentinel tarballs between 2026-07-27 01:02 and 05:36 UTC. Private registry mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs during the various publish windows (some dating back to 2026-03) WILL keep serving the original versions after the public yank

## What to do

1. Grep every lockfile (`package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`) for each name in the packages map below. Any match is a supply-chain incident: rotate every credential the build runner could reach and re-image the build host
2. **Highest-priority remediation - `thirdweb` / `rainbowkit` typosquat cluster**: if any of `therdweb`, `thidweb`, `thirdwb`, `thirdwebb`, `thirdwebjs`, `thurdweb`, `rainbokit`, `rainbownkit` appears in a lockfile, treat as a wallet-compromise event. Rotate every crypto wallet key, seed phrase, hot-wallet secret, and hardware-wallet PIN accessible from the dev host. Move funds via a clean device BEFORE attempting rotation. The 38-day exposure window means the wallet material may have been drained already - check on-chain balances first
3. **If any `@wrenfield/*` package appears**: same as above - the `abitype`/`viem` typosquats are wagmi/viem ecosystem-facing crypto-wallet targeting. Rotate wallet material, then rotate any adjacent developer credentials (npm tokens, GitHub tokens, cloud CLI tokens)
4. **If any Baileys-fork package appears** (`@fazzcode/baileys`, `sixbails`, `amanexzyra-baileys`, `@vinnxcode/xbailsync`, `@vinnxcode/libsignal-node`, `fazzanime`, `fazzgram`): the WhatsApp session cookie / auth-state files under `./auth_info_baileys/` are likely already exfiltrated. Rotate the paired WhatsApp account (logout all sessions from the WhatsApp mobile app, then re-pair with fresh QR), and treat any credentials handled by the bot process as compromised
5. **If any `@403name/*` package appears**: cross-check whether the intended dependency was `fsevents` (mistyped as `@403name/fsevent`), `electron-builder` (mistyped as `@403name/electron-buidler`), or `ethers` (mistyped as `@403name/ether-js`) - these are the canonical typosquats. All three versions (`1.0.0`, `1.0.1`, `1.0.2`) are compromised
6. **If any `txs-*` or `chai-log` package appears**: the same-day publish alignment on 2026-07-10 07:03–07:25 UTC implicates a single automated publisher; audit CI logs for `npm install` runs on that window and rotate CI-runner credentials
7. **If `ap3-components-ui@9.999.0` appears**: this is dependency-confusion - you have an INTERNAL package named `ap3-components-ui` that a public-registry lookup outranked. Configure your registry client to scope-restrict private packages (`.npmrc` scope-to-registry mapping), then rebuild the lockfile against the private registry. Rotate any secrets that were reachable from build hosts that installed the `9.999.0` version
8. **If any `@ceeferenderer/*` package appears**: same as above - the `9.9.9` / `99.9.9` inflated version numbers are dep-confusion. Even though the packages were on the registry since 2026-03, the 4-month dormancy means the exposure window is longer than most; audit build-host activity from 2026-03-13 forward
9. **If any `edu-npm-*` package appears**: nobody legitimately depends on these - a hit indicates either a compromised research-tool leak into production or an intentional install by a developer who typed the name manually. Investigate the human commit that added the dependency
10. For projects using `postinstall`-scripting packages, run `npm install --ignore-scripts` in CI as a defense-in-depth measure and invoke scripts only for vetted first-party packages
11. Verify none of the 47 listed packages still resolves via your private mirror - internal Artifactory / Nexus / Verdaccio instances routinely cache tarballs and will keep serving the original versions after the public yank
12. The sibling packages `@thone33/analytics-injector`, `@thone33/core-utils`, and `@thone33/react-helpers` were also in the 2026-07-27 batch - they are catalogued in `npm-2026-06-28-thone33-c2-stager-cluster`; `polymarket-stake-maths` was likewise in the batch and is catalogued in `npm-2026-07-17-polymarket-trap-clob-client-math`. Both are cross-referenced from this module rather than duplicated

## Check your own dependencies

- Check a package-lock.json against this incident: https://dependencywatch.io/check/package-lock-json

The scan runs entirely in the browser; lockfile contents are never uploaded.

## References

- [GitHub Advisory Database - recent npm malware advisories](https://github.com/advisories?query=type%3Amalware+ecosystem%3Anpm&sort=published-desc) - GitHub
- [GHSA-8jr3-m3cj-m436 - thirdwebjs malware advisory](https://github.com/advisories/GHSA-8jr3-m3cj-m436) - GitHub
- [GHSA-56vv-8v7m-r49g - rainbokit malware advisory](https://github.com/advisories/GHSA-56vv-8v7m-r49g) - GitHub
- [GHSA-vj5m-3jrw-83gx - rainbownkit malware advisory](https://github.com/advisories/GHSA-vj5m-3jrw-83gx) - GitHub
- [GHSA-g2vx-7x66-f2wv - therdweb malware advisory](https://github.com/advisories/GHSA-g2vx-7x66-f2wv) - GitHub
- [GHSA-ccmq-q5j8-hvxc - thirdwb malware advisory](https://github.com/advisories/GHSA-ccmq-q5j8-hvxc) - GitHub
- [GHSA-3vx6-4gr6-qj63 - thidweb malware advisory](https://github.com/advisories/GHSA-3vx6-4gr6-qj63) - GitHub
- [GHSA-46px-g2r9-8vcr - thirdwebb malware advisory](https://github.com/advisories/GHSA-46px-g2r9-8vcr) - GitHub
- [GHSA-vx4c-33rj-4xv8 - thurdweb malware advisory](https://github.com/advisories/GHSA-vx4c-33rj-4xv8) - GitHub
- [GHSA-6f83-g2m3-3wwr - @wrenfield/abitype malware advisory](https://github.com/advisories/GHSA-6f83-g2m3-3wwr) - GitHub
- [GHSA-pm4g-83cj-7858 - @wrenfield/viem malware advisory](https://github.com/advisories/GHSA-pm4g-83cj-7858) - GitHub
- [GHSA-wqqq-qm88-5433 - @fazzcode/baileys malware advisory](https://github.com/advisories/GHSA-wqqq-qm88-5433) - GitHub
- [GHSA-8cvc-378h-fwqf - sixbails malware advisory](https://github.com/advisories/GHSA-8cvc-378h-fwqf) - GitHub
- [GHSA-mwwh-7r57-h6v9 - amanexzyra-baileys malware advisory](https://github.com/advisories/GHSA-mwwh-7r57-h6v9) - GitHub
- [GHSA-v9rv-pgqp-436h - @vinnxcode/libsignal-node malware advisory](https://github.com/advisories/GHSA-v9rv-pgqp-436h) - GitHub
- [GHSA-fgwc-g3q5-794p - @vinnxcode/xbailsync malware advisory](https://github.com/advisories/GHSA-fgwc-g3q5-794p) - GitHub
- [GHSA-r3jh-34p6-m7xp - fazzanime malware advisory](https://github.com/advisories/GHSA-r3jh-34p6-m7xp) - GitHub
- [GHSA-vjhp-hr8c-42m8 - fazzgram malware advisory](https://github.com/advisories/GHSA-vjhp-hr8c-42m8) - GitHub
- [GHSA-x8v5-5q93-844w - log-taker malware advisory](https://github.com/advisories/GHSA-x8v5-5q93-844w) - GitHub
- [GHSA-35q5-q365-j23w - log-taker1 malware advisory](https://github.com/advisories/GHSA-35q5-q365-j23w) - GitHub
- [GHSA-fjgh-3fjv-prm3 - ts-escrow malware advisory](https://github.com/advisories/GHSA-fjgh-3fjv-prm3) - GitHub
- [GHSA-5hm9-jj3m-6q76 - ts-escro malware advisory](https://github.com/advisories/GHSA-5hm9-jj3m-6q76) - GitHub
- [GHSA-5g95-w82p-69v9 - txs-builder malware advisory](https://github.com/advisories/GHSA-5g95-w82p-69v9) - GitHub
- [GHSA-65pq-67vr-g3jp - txs-runner-lib malware advisory](https://github.com/advisories/GHSA-65pq-67vr-g3jp) - GitHub
- [GHSA-c2fc-52mv-g5v6 - txs-random-lib malware advisory](https://github.com/advisories/GHSA-c2fc-52mv-g5v6) - GitHub
- [GHSA-fgmc-rrjh-9m33 - txs-sdk-lib malware advisory](https://github.com/advisories/GHSA-fgmc-rrjh-9m33) - GitHub
- [GHSA-2534-xr99-f4wh - chai-log malware advisory](https://github.com/advisories/GHSA-2534-xr99-f4wh) - GitHub
- [GHSA-hp95-92q5-xfvc - @403name/fsevent malware advisory](https://github.com/advisories/GHSA-hp95-92q5-xfvc) - GitHub
- [GHSA-h23r-x34f-p95m - @403name/electron-buidler malware advisory](https://github.com/advisories/GHSA-h23r-x34f-p95m) - GitHub
- [GHSA-qgxg-2j6w-jmpx - @403name/ether-js malware advisory](https://github.com/advisories/GHSA-qgxg-2j6w-jmpx) - GitHub
- [GHSA-mw7m-6vvq-q69p - @ceeferenderer/fe-renderer-sdk malware advisory](https://github.com/advisories/GHSA-mw7m-6vvq-q69p) - GitHub
- [GHSA-3v4h-w4g3-h6r2 - @ceeferenderer/itg-renderer-sdk malware advisory](https://github.com/advisories/GHSA-3v4h-w4g3-h6r2) - GitHub
- [GHSA-qhgr-v9vh-3784 - ap3-components-ui malware advisory](https://github.com/advisories/GHSA-qhgr-v9vh-3784) - GitHub
- [GHSA-gj4r-435f-67cr - fluterjs malware advisory](https://github.com/advisories/GHSA-gj4r-435f-67cr) - GitHub
- [GHSA-g6f3-9j93-879j - kalipto-runtime malware advisory](https://github.com/advisories/GHSA-g6f3-9j93-879j) - GitHub
- [GHSA-653g-2cfx-6gpc - @kalipto/local malware advisory](https://github.com/advisories/GHSA-653g-2cfx-6gpc) - GitHub
- [GHSA-9499-pgrg-v7w7 - permcarmserver malware advisory](https://github.com/advisories/GHSA-9499-pgrg-v7w7) - GitHub
- [GHSA-vjr2-cx8x-3q2x - permcserver malware advisory](https://github.com/advisories/GHSA-vjr2-cx8x-3q2x) - GitHub
- [GHSA-hmpp-mfgc-mq8p - roblox-api-client malware advisory](https://github.com/advisories/GHSA-hmpp-mfgc-mq8p) - GitHub
- [GHSA-3mmq-8798-7f4v - npx-whoami-demo malware advisory](https://github.com/advisories/GHSA-3mmq-8798-7f4v) - GitHub
- [GHSA-q86v-7cxj-6979 - @ci-lifecycle-test/postinstall-ping malware advisory](https://github.com/advisories/GHSA-q86v-7cxj-6979) - GitHub
- [GHSA-cw6g-r53q-23c2 - v018-axios-cdntest malware advisory](https://github.com/advisories/GHSA-cw6g-r53q-23c2) - GitHub
- [GHSA-fvh5-fhfx-3whm - jextic-eclib malware advisory](https://github.com/advisories/GHSA-fvh5-fhfx-3whm) - GitHub
- [GHSA-cqgx-r84j-px55 - edu-npm-dependency-chain-demo malware advisory](https://github.com/advisories/GHSA-cqgx-r84j-px55) - GitHub
- [GHSA-mm62-vp6v-vqq2 - edu-npm-helper-beta malware advisory](https://github.com/advisories/GHSA-mm62-vp6v-vqq2) - GitHub
- [GHSA-jhpp-p77r-39q6 - edu-npm-helper-alpha malware advisory](https://github.com/advisories/GHSA-jhpp-p77r-39q6) - GitHub
- [GHSA-gqxv-6fpm-5xwx - edu-npm-postinstall-demo2 malware advisory](https://github.com/advisories/GHSA-gqxv-6fpm-5xwx) - GitHub

---

Canonical page: https://dependencywatch.io/incident/npm-2026-07-27-ghsa-malware-sweep
Markdown version: https://dependencywatch.io/incident/npm-2026-07-27-ghsa-malware-sweep.md
Site index for agents: https://dependencywatch.io/llms.txt
DependencyWatch.io is operated by Precursor Security (https://precursorsecurity.com).
