# GitHub Advisory npm CWE-506 mega-sweep - 54-package sample from the 2026-07-27 → 2026-07-28 batch (8-package Ethereum-tooling `curl|bash` typosquat cluster, chalk / express / prettier / prisma / dotenv / chai-as-promised typosquat pairs, "helper/utils/tool/pack" credential+wallet-stealer family, 13-package dep-confusion cluster with `999.x` / `19999.x` / `99.99.99` version-inflation, Shai-Hulud-style preinstall Bun stealer resurgence, `@vaultflow/*` 2026-07-28 pair, `claude-code-base-action` Anthropic typosquat)

> GitHub Advisory Database published a mega-batch of **250+ new npm CWE-506 malware advisories on 2026-07-27** (spanning 12+ paginated result pages), plus 2 more on 2026-07-28 (`@vaultflow/create-flow`, `@vaultflow/update-flow`). This module catalogues 54 non-`@antv` non-previously-tracked packages from the batch. Notable clusters: 8-package Ethereum-tooling `curl|bash` operator (`web3-core-js`, `truffle-js`, `truffle-helper`, `solc-helper`, `hardhat-core`, `ethers-common`, `ethers-io`, `cdp-core`), typosquat pairs (`chalk-*`, `exxpress-*`, `prettier-lint-lenz`, `prisma-callback`, `env-threads`), dep-confusion with inflated version numbers (`999.x`, `19999.x`, `99.99.99`), and Shai-Hulud-style preinstall Bun credential stealers on `mcp-echarts`, `mcp-mermaid`, `ai-figure`, `gantt-for-react`, `amapcn`, `boring-avatars-vanilla`, `jest-canvas-mock`, `@cap-js/openapi`.

- Published: 2026-07-28
- Severity: high
- Kind: Advisory sweep - A dated batch of GitHub Advisory Database malware entries collected together. A sweep mixes kinds - typosquats, dependency-confusion probes, boilerplate takedowns with no published analysis, and occasionally real payloads - and its severity reflects the worst confirmed item, not the batch as a whole.
- Ecosystems: npm
- Scope: 54 packages, 125 compromised versions
- Tags: typosquat, crypto-wallet-drain, credential-theft, dependency-confusion, infostealer, worm, ci-cd-compromise, obfuscation
- Also known as: 2026-07-27 GHSA npm mega-sweep, Ethereum-tooling curl|bash cluster, helper/utils/tool/pack typosquat kit, Shai-Hulud AntV-adjacent resurgence
- Detected by: GitHub Advisory Database, npm Security
- Incident ID: npm-2026-07-28-ghsa-malware-sweep

## Affected packages (54)

Only the exact versions listed were named by the source advisories. Other versions are not implicated.

| Package | Ecosystem | Compromised versions |
|---|---|---|
| [@apps-home-dashboard/events](https://dependencywatch.io/package/npm/@apps-home-dashboard/events) | npm | 11.9.0, 11.9.1 |
| [@cap-js/openapi](https://dependencywatch.io/package/npm/@cap-js/openapi) | npm | 1.4.1 |
| [@citi-icg-158830/elemental-chameleon](https://dependencywatch.io/package/npm/@citi-icg-158830/elemental-chameleon) | npm | 0.0.0-defensive-callback, 0.0.0-defensive-callback.1 |
| [@convera/ui-shared](https://dependencywatch.io/package/npm/@convera/ui-shared) | npm | 0.0.2, 0.0.3 |
| [@datatrain/passenger-v3](https://dependencywatch.io/package/npm/@datatrain/passenger-v3) | npm | 99.99.99 |
| [@design-system-coopeuch/web](https://dependencywatch.io/package/npm/@design-system-coopeuch/web) | npm | 999.0.0, 999.0.4 |
| [@pelmnaads/naads-common-logger](https://dependencywatch.io/package/npm/@pelmnaads/naads-common-logger) | npm | 19999.0.1 |
| [@tc-core/campus-service](https://dependencywatch.io/package/npm/@tc-core/campus-service) | npm | 0.0.0-defensive-callback |
| [@vaultflow/create-flow](https://dependencywatch.io/package/npm/@vaultflow/create-flow) | npm | 1.0.0 |
| [@vaultflow/update-flow](https://dependencywatch.io/package/npm/@vaultflow/update-flow) | npm | 1.0.0 |
| [@webapp-next/store](https://dependencywatch.io/package/npm/@webapp-next/store) | npm | 91.1.0 |
| [ai-figure](https://dependencywatch.io/package/npm/ai-figure) | npm | 0.5.0, 0.6.0 |
| [amapcn](https://dependencywatch.io/package/npm/amapcn) | npm | 0.2.0, 0.2.1, 0.2.2, 0.3.0, 0.3.1, 0.3.2 |
| [apex-connector](https://dependencywatch.io/package/npm/apex-connector) | npm | 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4 |
| [apex-trading](https://dependencywatch.io/package/npm/apex-trading) | npm | 1.0.4 |
| [boring-avatars-vanilla](https://dependencywatch.io/package/npm/boring-avatars-vanilla) | npm | 1.1.2, 1.2.2 |
| [bui-react-10components](https://dependencywatch.io/package/npm/bui-react-10components) | npm | 99.0.0 |
| [cache-poisoning-pwn-demo](https://dependencywatch.io/package/npm/cache-poisoning-pwn-demo) | npm | 0.1.27, 0.1.28, 0.1.29 |
| [cdp-core](https://dependencywatch.io/package/npm/cdp-core) | npm | 1.0.4, 1.0.6 |
| [chai-as-regulated](https://dependencywatch.io/package/npm/chai-as-regulated) | npm | 2.0.10, 2.0.11, 2.0.12 |
| [chalk-pack](https://dependencywatch.io/package/npm/chalk-pack) | npm | 1.0.4, 2.0.0 |
| [chalk-utils](https://dependencywatch.io/package/npm/chalk-utils) | npm | 1.0.3, 1.0.4, 2.0.0 |
| [cheerio-tool](https://dependencywatch.io/package/npm/cheerio-tool) | npm | 1.0.3, 1.0.4, 1.0.5 |
| [claude-code-base-action](https://dependencywatch.io/package/npm/claude-code-base-action) | npm | 2.0.0, 2.2.2 |
| [dotenvv-tool](https://dependencywatch.io/package/npm/dotenvv-tool) | npm | 1.0.2, 1.0.3, 1.0.4, 1.0.5, 2.0.0 |
| [env-threads](https://dependencywatch.io/package/npm/env-threads) | npm | 1.5.0 |
| [ethers-common](https://dependencywatch.io/package/npm/ethers-common) | npm | 1.0.0, 2.0.0 |
| [ethers-io](https://dependencywatch.io/package/npm/ethers-io) | npm | 1.0.0, 2.0.0 |
| [exxpress-tool](https://dependencywatch.io/package/npm/exxpress-tool) | npm | 1.0.0, 1.0.2, 1.0.5 |
| [exxpress-utils](https://dependencywatch.io/package/npm/exxpress-utils) | npm | 1.0.2, 1.0.3, 1.0.5, 2.0.0 |
| [gantt-for-react](https://dependencywatch.io/package/npm/gantt-for-react) | npm | 0.3.0, 0.4.0 |
| [glob-helper](https://dependencywatch.io/package/npm/glob-helper) | npm | 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 2.0.0 |
| [hardhat-core](https://dependencywatch.io/package/npm/hardhat-core) | npm | 1.0.0, 2.0.0 |
| [hello-world-pkg-value-value-p](https://dependencywatch.io/package/npm/hello-world-pkg-value-value-p) | npm | 1.0.4, 1.0.11 |
| [identitysecuretokenserv](https://dependencywatch.io/package/npm/identitysecuretokenserv) | npm | 10.0.0, 20.0.0 |
| [jest-canvas-mock](https://dependencywatch.io/package/npm/jest-canvas-mock) | npm | 2.5.3, 2.6.3, 2.7.3 |
| [joi-pack](https://dependencywatch.io/package/npm/joi-pack) | npm | 1.0.3, 1.0.4, 1.0.5 |
| [mcp-echarts](https://dependencywatch.io/package/npm/mcp-echarts) | npm | 0.8.1, 0.9.1 |
| [mcp-mermaid](https://dependencywatch.io/package/npm/mcp-mermaid) | npm | 0.5.1, 0.6.1 |
| [motion-forge-css](https://dependencywatch.io/package/npm/motion-forge-css) | npm | 1.0.0 |
| [nock-helper](https://dependencywatch.io/package/npm/nock-helper) | npm | 1.0.2, 1.0.3, 1.0.4, 1.0.5, 2.0.0 |
| [node-ci-utils](https://dependencywatch.io/package/npm/node-ci-utils) | npm | 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4 |
| [paysafe-gbp-virtual-assistant-lib-fe](https://dependencywatch.io/package/npm/paysafe-gbp-virtual-assistant-lib-fe) | npm | 2.0.4 |
| [prettier-lint-lenz](https://dependencywatch.io/package/npm/prettier-lint-lenz) | npm | 1.0.0, 2.6.4 |
| [prisma-callback](https://dependencywatch.io/package/npm/prisma-callback) | npm | 1.0.0, 1.0.3, 1.0.4, 1.0.5 |
| [request-logger-canary](https://dependencywatch.io/package/npm/request-logger-canary) | npm | 1.0.0 |
| [rimraf-utils](https://dependencywatch.io/package/npm/rimraf-utils) | npm | 1.0.4, 1.0.5, 2.0.0 |
| [solc-helper](https://dependencywatch.io/package/npm/solc-helper) | npm | 1.0.0, 2.0.0 |
| [sysbin](https://dependencywatch.io/package/npm/sysbin) | npm | 1.0.34 |
| [truffle-helper](https://dependencywatch.io/package/npm/truffle-helper) | npm | 1.0.0, 2.0.0 |
| [truffle-js](https://dependencywatch.io/package/npm/truffle-js) | npm | 1.0.0, 2.0.0 |
| [typography-stylecss](https://dependencywatch.io/package/npm/typography-stylecss) | npm | 0.7.4 |
| [vue-template-compiler-plugin](https://dependencywatch.io/package/npm/vue-template-compiler-plugin) | npm | 2.7.18 |
| [web3-core-js](https://dependencywatch.io/package/npm/web3-core-js) | npm | 1.0.0, 2.0.0 |

## What happened

On 2026-07-27 and 2026-07-28, the GitHub Advisory Database published a **mega-batch of new npm CWE-506 (Embedded Malicious Code) advisories** - 250+ advisories on 2026-07-27 alone (spanning 12+ paginated result pages) plus 2 more on 2026-07-28 (`@vaultflow/create-flow`, `@vaultflow/update-flow`). The batch shape strongly suggests a coordinated backfill of longstanding malware carried out on the back of an upstream signal - likely OpenSSF Package Analysis feeding into GHSA in bulk, or npm-security scheduling a queue of packages that had accumulated triage-flags.

This module catalogues **54 packages from the batch** - the non-`@antv/*` and non-previously-tracked advisories with confirmed affected versions. The balance of the 250+ batch is dominated by GHSA backfill of the pre-existing `@antv/*` Mini Shai-Hulud incident (`npm-2026-05-19-antv-mini-shai-hulud`, 261 packages already tracked) - those advisories are cross-referenced from the AntV module which has been bumped to `lastUpdated: 2026-07-28` for this ingest.

## Cluster 1 - Ethereum-tooling `curl|bash` typosquat operator (8 packages)

| Package | Versions | Target |
|---|---|---|
| `web3-core-js` | `1.0.0`, `2.0.0` | `web3.js` (Web3 library) |
| `truffle-js` | `1.0.0`, `2.0.0` | `truffle` (dev framework) |
| `truffle-helper` | `1.0.0`, `2.0.0` | `truffle` |
| `solc-helper` | `1.0.0`, `2.0.0` | `solc` (Solidity compiler) |
| `hardhat-core` | (≥1.0.0) | `hardhat` (dev environment) |
| `ethers-common` | `1.0.0`, `2.0.0` | `ethers.js` (Ethereum JS SDK) |
| `ethers-io` | `1.0.0`, `2.0.0` | `ethers.js` |
| `cdp-core` | `1.0.4`, `1.0.6` | Coinbase `@coinbase/cdp-sdk` |

All eight run near-identical postinstall hooks: base64-decode a URL, `curl` it over plain HTTP, pipe the response to `bash`. The identical `1.0.0` / `2.0.0` two-version publish signature on 7 of the 8 (plus `cdp-core` on a different version pattern) is a strong operator-overlap signal.

## Cluster 2 - "helper/utils/tool/pack" credential+wallet stealer family (10 packages)

| Package | Versions | Target |
|---|---|---|
| `chalk-pack` | `1.0.4`, `2.0.0` | `chalk` |
| `chalk-utils` | `1.0.3`, `1.0.4`, `2.0.0` | `chalk` |
| `exxpress-utils` | `1.0.2`, `1.0.3`, `1.0.5`, `2.0.0` | `express` (double-x typo) |
| `exxpress-tool` | `1.0.0`, `1.0.2`, `1.0.5` | `express` |
| `dotenvv-tool` | `1.0.2`–`2.0.0` | `dotenv` (double-v typo) |
| `joi-pack` | `1.0.3`, `1.0.4`, `1.0.5` | `joi` |
| `nock-helper` | `1.0.2`–`2.0.0` | `nock` |
| `cheerio-tool` | `1.0.3`, `1.0.4`, `1.0.5` | `cheerio` |
| `glob-helper` | `1.0.0`–`2.0.0` | `glob` |
| `rimraf-utils` | `1.0.4`, `1.0.5`, `2.0.0` | `rimraf` |

All ten use the same "helper/utils/tool/pack" suffix convention on a well-known dependency name and share an identical postinstall payload that reads `~/.npmrc`, `~/.env`, `~/.git-credentials`, and every browser wallet-extension's storage directory, POSTing the harvested material to a static C2 endpoint. Very likely a single operator using an automated typosquat kit.

## Cluster 3 - Shai-Hulud-style preinstall Bun credential stealer resurgence (8 packages)

| Package | Versions | Notes |
|---|---|---|
| `boring-avatars-vanilla` | `1.1.2`, `1.2.2` | `boring-avatars` typosquat |
| `jest-canvas-mock` | `2.5.3`, `2.6.3`, `2.7.3` | canonical `jest-canvas-mock` hijack - dep-name reuse |
| `mcp-echarts` | `0.8.1`, `0.9.1` | AntV-family MCP server |
| `mcp-mermaid` | `0.5.1`, `0.6.1` | AntV-family MCP server |
| `ai-figure` | `0.5.0`, `0.6.0` | AntV-adjacent |
| `gantt-for-react` | `0.3.0`, `0.4.0` | AntV-adjacent |
| `amapcn` | (`≤0.2.2` and `≤0.3.2`) | AMap (AntV/Alipay family) |
| `@cap-js/openapi` | `1.4.1` | SAP CAP-JS - same scope as 2026-04 `npm-2026-04-sap-cap-js` |

All eight use the same ~498KB obfuscated Bun-runtime preinstall payload previously documented in the 2026-05-11 TanStack + Mini Shai-Hulud campaign and the 2026-05-19 AntV wave. Behaviours: AWS IMDSv2 + GCP metadata + Azure managed identity scrape, Kubernetes SA-token theft, HashiCorp Vault reads, npm/GitHub token exfil via GitHub API, then CI/CD workflow injection for persistence.

The AntV-adjacent hits and the `@cap-js/openapi` addition strongly suggest GHSA is backfilling packages that were part of the same worm-family activity but missed in the original triage. Treat these as **critical**, same-worm-family exposure.

## Cluster 4 - dep-confusion via inflated version numbers (13 packages)

| Package | Version | Notes |
|---|---|---|
| `@webapp-next/store` | `91.1.0` | scoped internal-name |
| `@design-system-coopeuch/web` | `999.0.0`, `999.0.4` | 999.x major |
| `@pelmnaads/naads-common-logger` | `19999.0.1` | 5-digit major |
| `bui-react-10components` | `99.0.0` | 99.x major |
| `@datatrain/passenger-v3` | `99.99.99` | classic 99.99.99 dep-confusion |
| `identitysecuretokenserv` | `10.0.0`, `20.0.0` | non-scoped internal-lib name |
| `paysafe-gbp-virtual-assistant-lib-fe` | `2.0.4` | Paysafe internal-lib (see `multi-2026-07-07-paysafe-skrill-payment-sdk-typosquat`) |
| `@convera/ui-shared` | `0.0.2`, `0.0.3` | scoped internal-name (Convera fintech) |
| `@apps-home-dashboard/events` | (≤11.9.1) | scoped internal-name |
| `apex-trading` | `1.0.4` | trading-platform impersonation |
| `apex-connector` | (≤1.0.4) | trading-platform impersonation |
| `@tc-core/campus-service` | `0.0.0-defensive-callback` | prerelease-tag "defensive-callback" - probable research-tooling probe |
| `@citi-icg-158830/elemental-chameleon` | `0.0.0-defensive-callback`, `.1` | Citi ICG scope with defensive-callback tag - probable research probe |

The `0.0.0-defensive-callback` prerelease-tag naming on the `@tc-core/*` and `@citi-icg-158830/*` entries is distinctive. It reads as an automated dep-confusion probe kit (Snyk's Fetch service, CodeSec's Chain-Bench, or a similar researcher-owned tool) that GHSA is flagging out of caution. The other 11 entries in this cluster are classical attacker-controlled dep-confusion.

## Cluster 5 - misc typosquats and RATs (12 packages)

| Package | Versions | Notes |
|---|---|---|
| `sysbin` | `1.0.34` | clipboard + screenshot exfil Python stager |
| `vue-template-compiler-plugin` | `2.7.18` | full RAT with C2 beacon |
| `typography-stylecss` | `0.7.4` | `@tailwindcss/typography` typosquat, binary dropper |
| `env-threads` | `1.5.0` | dotenv typosquat, steganographic JPEG payload |
| `chai-as-regulated` | (≤2.0.12) | `chai-as-promised` typosquat, silent bg process |
| `prettier-lint-lenz` | `1.0.0`, `2.6.4` | prettier typosquat, clipboard-stealing trojan |
| `prisma-callback` | `1.0.0`, `1.0.3`–`1.0.5` | prisma typosquat, opaque compiled binary |
| `hello-world-pkg-value-value-p` | `1.0.4`, `1.0.11` | reverse shell → `52.249.218.132:8080` (Azure IP) |
| `request-logger-canary` | `1.0.0` | reverse shell on install |
| `cache-poisoning-pwn-demo` | `0.1.27`–`0.1.29` | explicit PoC dropping `calc.exe` |
| `node-ci-utils` | (≤2.1.4) | opaque binary downloader |
| `motion-forge-css` | (all versions) | embedded malicious code |
| `claude-code-base-action` | `2.0.0`, `2.2.2` | typosquat of `anthropics/claude-code-base-action` GitHub Action |

## 2026-07-28 - `@vaultflow/*` pair

| Package | Versions | Notes |
|---|---|---|
| `@vaultflow/update-flow` | (all versions) | HashiCorp Vault tooling scope, secret/key stealer |
| `@vaultflow/create-flow` | (all versions) | HashiCorp Vault tooling scope, secret/key stealer |

Coordinated same-scope publish on 2026-07-28 (the only two 2026-07-28-dated advisories in the batch). Both flagged as `>=0` all-versions in the advisory range.

## Registry state

All 54 packages security-replaced with `0.0.1-security` sentinel tarballs. Original version tarballs are no longer resolvable on the public registry, but private registry mirrors that cached the tarballs BEFORE the takedown WILL keep serving the original versions.

## Related tracked activity

- The pre-existing `npm-2026-05-19-antv-mini-shai-hulud` module (261 packages) covers the bulk of the 2026-07-27 batch's `@antv/*` backfill and has been bumped on this ingest.
- `@cap-js/openapi` extends the SAP CAP-JS attack surface previously documented in `npm-2026-04-sap-cap-js` and `npm-2026-05-shai-hulud-tanstack` (which also covers `@cap-js/*`).
- `paysafe-gbp-virtual-assistant-lib-fe` extends the Paysafe-internal-lib impersonation campaign in `multi-2026-07-07-paysafe-skrill-payment-sdk-typosquat`.
- The Ethereum-tooling `curl|bash` cluster (Cluster 1) is a fresh operator not previously catalogued.

## Impact

- Any host that installed any of the 54 packages listed below should be treated as fully compromised - every GHSA record uses the boilerplate CWE-506 "any computer that has this package installed or running should be considered fully compromised - rotate all secrets from a different computer" language, and no patched version exists
- **Cluster 1 - Ethereum-tooling `curl|bash` typosquat operator** (8 packages, all published 2026-07-27 with the identical `1.0.0` / `2.0.0` two-version signature except `cdp-core`): `web3-core-js`, `truffle-js`, `truffle-helper`, `solc-helper`, `hardhat-core`, `ethers-common`, `ethers-io`, `cdp-core`. All eight run near-identical postinstall lifecycle hooks that base64-decode a URL, `curl` it over plain HTTP, and pipe the response to `bash` - a classic stager pattern. Each name typosquats a household Ethereum tool: `web3.js` (Web3 library), `truffle` (dev framework), `solc` (Solidity compiler), `hardhat` (dev environment), `ethers.js` (Ethereum JS SDK), Coinbase `@coinbase/cdp-sdk` (CDP-Core wallet SDK). Operator overlap near-certain: same TTP, same publish date, same version pattern
- **Cluster 2 - "helper/utils/tool/pack" credential+wallet stealer family** (10 packages, same postinstall signature reading `~/.npmrc`, `~/.env`, `~/.git-credentials`, plus browser wallet-extension directories): `chalk-pack`, `chalk-utils` (chalk typosquat pair), `exxpress-utils`, `exxpress-tool` (express typosquat pair - double-x), `dotenvv-tool` (dotenv typosquat), `joi-pack` (joi typosquat), `nock-helper` (nock typosquat), `cheerio-tool` (cheerio typosquat), `glob-helper` (glob typosquat), `rimraf-utils` (rimraf typosquat). All ten use the same "helper/utils/tool/pack" suffix convention on a well-known dependency name - very likely a single operator using an automated typosquat kit
- **Cluster 3 - Shai-Hulud-style preinstall Bun credential stealer resurgence** (8 packages): `boring-avatars-vanilla`, `jest-canvas-mock`, `mcp-echarts`, `mcp-mermaid`, `ai-figure`, `gantt-for-react`, `amapcn`, `@cap-js/openapi`. All use the same ~498KB obfuscated Bun-runtime preinstall payload documented in the 2026-05-11 TanStack + Mini Shai-Hulud campaign (`npm-2026-05-shai-hulud-tanstack`) and the 2026-05-19 AntV wave (`npm-2026-05-19-antv-mini-shai-hulud`): AWS IMDSv2 + GCP metadata + Azure managed identity scrape, Kubernetes SA-token theft, HashiCorp Vault reads, npm/GitHub token exfil via GitHub API, then CI/CD workflow injection for persistence. The AntV-adjacent hits (`mcp-echarts`, `mcp-mermaid` - visualisation MCP servers; `ai-figure`, `gantt-for-react`, `amapcn` - AMap is part of the AntV/Alipay ecosystem) and `@cap-js/openapi` (SAP CAP-JS scope, matching the 2026-04 `npm-2026-04-sap-cap-js` incident) strongly suggest GHSA is backfilling packages missed in the original triage - treat these as **critical**, same-worm-family exposure
- **Cluster 4 - dep-confusion via inflated version numbers** (13 packages, all target internal-scope names with absurdly-high semver): `@webapp-next/store@91.1.0`, `@design-system-coopeuch/web@999.0.0`/`999.0.4`, `@pelmnaads/naads-common-logger@19999.0.1` (a five-digit major version), `bui-react-10components@99.0.0`, `@datatrain/passenger-v3@99.99.99`, `identitysecuretokenserv@10.0.0`/`20.0.0`, `paysafe-gbp-virtual-assistant-lib-fe@2.0.4` (Paysafe internal-lib impersonation matching `multi-2026-07-07-paysafe-skrill-payment-sdk-typosquat`), `@convera/ui-shared@0.0.2`/`0.0.3`, `@apps-home-dashboard/events` (≤11.9.1), `apex-trading@1.0.4`, `apex-connector` (≤1.0.4), `@tc-core/campus-service@0.0.0-defensive-callback`, `@citi-icg-158830/elemental-chameleon@0.0.0-defensive-callback`/`.1`. The `0.0.0-defensive-callback` prerelease-tag naming on `@tc-core/*` and `@citi-icg-158830/*` looks like an automated dep-confusion probe kit - likely Snyk/CodeSec research tooling that GHSA is flagging out of caution
- **Cluster 5 - misc typosquats and RATs**: `sysbin@1.0.34` (clipboard + screenshot exfiltration Python stager), `vue-template-compiler-plugin@2.7.18` (full RAT with C2 beacon), `typography-stylecss@0.7.4` (`@tailwindcss/typography` typosquat, binary dropper), `env-threads@1.5.0` (dotenv typosquat with steganographic JPEG payload), `chai-as-regulated` (≤2.0.12) (`chai-as-promised` typosquat, silent bg process), `prettier-lint-lenz@1.0.0`/`2.6.4` (prettier typosquat, clipboard-stealing trojan), `prisma-callback@1.0.0`/`1.0.3`–`1.0.5` (prisma typosquat, opaque compiled binary), `hello-world-pkg-value-value-p@1.0.4`/`1.0.11` (reverse shell → `52.249.218.132:8080`), `request-logger-canary@1.0.0` (reverse shell on install), `cache-poisoning-pwn-demo@0.1.27`–`0.1.29` (explicit PoC dropping `calc.exe`), `node-ci-utils` (≤2.1.4) (opaque binary downloader), `motion-forge-css` (all versions), `claude-code-base-action@2.0.0`/`2.2.2` (typosquat of `anthropics/claude-code-base-action` GitHub Action - a supply-chain angle on Anthropic's official CLI Action)
- **2026-07-28 - `@vaultflow/*` pair**: `@vaultflow/update-flow`, `@vaultflow/create-flow` - a coordinated same-scope publish targeting HashiCorp Vault workflow tooling; both flagged as `>=0` (all-versions) secret-stealers on the day of ingest
- None of the 54 packages have surviving version tarballs on the public npm registry - all replaced with `0.0.1-security` sentinel tarballs during the 2026-07-27 → 2026-07-28 batch. Private registry mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs BEFORE the takedown WILL keep serving the original versions

## What to do

1. Grep every lockfile (`package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`) for each name in the packages map below. Any match is a supply-chain incident: rotate every credential the build runner could reach and re-image the build host
2. **Highest-priority remediation - Cluster 3 (Shai-Hulud family)**: any hit on `boring-avatars-vanilla`, `jest-canvas-mock`, `mcp-echarts`, `mcp-mermaid`, `ai-figure`, `gantt-for-react`, `amapcn`, or `@cap-js/openapi` at the listed versions requires the full TanStack/AntV Mini Shai-Hulud remediation: rotate npm tokens, GitHub PATs + OIDC trust relationships, AWS IAM keys reachable from build hosts, GCP service-account credentials, Azure managed-identity tokens, Kubernetes service-account tokens, HashiCorp Vault tokens, and every CI/CD secret. Audit `.github/workflows/` for injected steps
3. **Cluster 1 (Ethereum tooling)** - if any of `web3-core-js`, `truffle-js`, `truffle-helper`, `solc-helper`, `hardhat-core`, `ethers-common`, `ethers-io`, `cdp-core` appears in a lockfile: treat as a wallet-compromise event. Rotate every crypto wallet key, seed phrase, and hardware-wallet PIN accessible from the dev host. Move funds via a clean device BEFORE attempting rotation. Verify what the `curl|bash` stager actually executed by inspecting outbound HTTP logs
4. **Cluster 2 (credential+wallet stealer family)** - if any of `chalk-pack`, `chalk-utils`, `exxpress-utils`, `exxpress-tool`, `dotenvv-tool`, `joi-pack`, `nock-helper`, `cheerio-tool`, `glob-helper`, `rimraf-utils` appears: `~/.npmrc`, `~/.env`, `~/.git-credentials`, and every browser wallet extension's storage are considered exfiltrated. Rotate npm tokens, GitHub credentials, every secret in `.env`, and re-key crypto wallets
5. **Cluster 4 (dep-confusion inflated-version)** - if any of the `999.x` / `19999.x` / `99.99.99` / `99.0.0` / `91.1.0` / `10.0.0` / `20.0.0` packages listed appears: you have an INTERNAL package the attacker guessed; configure your registry client to scope-restrict private packages (`.npmrc` `@scope:registry=` mapping), then rebuild the lockfile against the private registry. Rotate secrets reachable from build hosts. For the `0.0.0-defensive-callback` prerelease-tag entries (`@tc-core/campus-service`, `@citi-icg-158830/elemental-chameleon`), the naming looks like a research-tooling artefact - investigate whether the hit represents a Snyk/CodeSec probe or a live compromise
6. **`paysafe-gbp-virtual-assistant-lib-fe@2.0.4`** - cross-reference with `multi-2026-07-07-paysafe-skrill-payment-sdk-typosquat`; this is the same Paysafe-internal-lib impersonation campaign continuing three weeks later. If any `paysafe-*` name appears, rotate every Paysafe/Skrill integration credential and audit build-host activity
7. **`claude-code-base-action@2.0.0`/`2.2.2`** - this typosquats the legitimate `anthropics/claude-code-base-action` GitHub Action. Any `.github/workflows/*.yml` file referencing `uses: <someone-else>/claude-code-base-action@` is compromised; the canonical action is `uses: anthropics/claude-code-base-action@v1` (or a specific released tag)
8. **`@vaultflow/*` (2026-07-28)** - treat as HashiCorp Vault credential exfiltration. Rotate every Vault token, root token, and audit-log-visible client identity that could have been reachable
9. For projects using `postinstall`-scripting packages, run `npm install --ignore-scripts` in CI as defense-in-depth and invoke scripts only for vetted first-party packages
10. Verify none of the 54 listed packages still resolves via your private mirror - internal Artifactory / Nexus / Verdaccio instances routinely cache tarballs and will keep serving the original versions after the public yank
11. Broader batch context: the 2026-07-27 GitHub Advisory Database batch spans **250+ CWE-506 advisories** (12+ pages of paginated results, all dated 2026-07-27). This module catalogues 54; the balance is dominated by GHSA backfill of the pre-existing `@antv/*` Mini Shai-Hulud incident (`npm-2026-05-19-antv-mini-shai-hulud`, published 2026-05-19), which has been updated on this ingest to reflect the ongoing formal-advisory cataloguing of packages already tracked in its 261-package map

## Check your own dependencies

- Check a package-lock.json against this incident: https://dependencywatch.io/check/package-lock-json

The scan runs entirely in the browser; lockfile contents are never uploaded.

## References

- [GitHub Advisory Database - recent npm malware advisories](https://github.com/advisories?query=type%3Amalware+ecosystem%3Anpm&sort=published-desc) - GitHub
- [GHSA-gv55-mvjq-232h - @vaultflow/update-flow malware advisory](https://github.com/advisories/GHSA-gv55-mvjq-232h) - GitHub
- [GHSA-xpp9-qw49-cpw2 - @vaultflow/create-flow malware advisory](https://github.com/advisories/GHSA-xpp9-qw49-cpw2) - GitHub
- [GHSA-f75h-gv5f-cg2x - web3-core-js malware advisory](https://github.com/advisories/GHSA-f75h-gv5f-cg2x) - GitHub
- [GHSA-7cmq-x9fp-ppg5 - truffle-js malware advisory](https://github.com/advisories/GHSA-7cmq-x9fp-ppg5) - GitHub
- [GHSA-2cq2-c7vh-j55c - truffle-helper malware advisory](https://github.com/advisories/GHSA-2cq2-c7vh-j55c) - GitHub
- [GHSA-8mmw-f9x4-8m2v - solc-helper malware advisory](https://github.com/advisories/GHSA-8mmw-f9x4-8m2v) - GitHub
- [GHSA-6rxh-8gx9-544x - hardhat-core malware advisory](https://github.com/advisories/GHSA-6rxh-8gx9-544x) - GitHub
- [GHSA-853h-mq9w-93p4 - ethers-common malware advisory](https://github.com/advisories/GHSA-853h-mq9w-93p4) - GitHub
- [GHSA-rmhg-qfp9-hvvm - ethers-io malware advisory](https://github.com/advisories/GHSA-rmhg-qfp9-hvvm) - GitHub
- [GHSA-xc49-p4pq-83rq - cdp-core malware advisory](https://github.com/advisories/GHSA-xc49-p4pq-83rq) - GitHub
- [GHSA-v7hx-pp9r-7rvr - chalk-pack malware advisory](https://github.com/advisories/GHSA-v7hx-pp9r-7rvr) - GitHub
- [GHSA-qfhf-894c-75p7 - chalk-utils malware advisory](https://github.com/advisories/GHSA-qfhf-894c-75p7) - GitHub
- [GHSA-pjc4-9jjg-gqx4 - exxpress-utils malware advisory](https://github.com/advisories/GHSA-pjc4-9jjg-gqx4) - GitHub
- [GHSA-xfj5-439g-p6qm - exxpress-tool malware advisory](https://github.com/advisories/GHSA-xfj5-439g-p6qm) - GitHub
- [GHSA-v6vw-vv5w-p658 - dotenvv-tool malware advisory](https://github.com/advisories/GHSA-v6vw-vv5w-p658) - GitHub
- [GHSA-2p7q-46c9-cjgf - joi-pack malware advisory](https://github.com/advisories/GHSA-2p7q-46c9-cjgf) - GitHub
- [GHSA-335w-3phj-h2jj - nock-helper malware advisory](https://github.com/advisories/GHSA-335w-3phj-h2jj) - GitHub
- [GHSA-34x4-g9xm-gjmw - cheerio-tool malware advisory](https://github.com/advisories/GHSA-34x4-g9xm-gjmw) - GitHub
- [GHSA-5f9h-7gp2-hg2m - glob-helper malware advisory](https://github.com/advisories/GHSA-5f9h-7gp2-hg2m) - GitHub
- [GHSA-9fg9-r489-hq34 - rimraf-utils malware advisory](https://github.com/advisories/GHSA-9fg9-r489-hq34) - GitHub
- [GHSA-37pp-fr38-g266 - boring-avatars-vanilla malware advisory](https://github.com/advisories/GHSA-37pp-fr38-g266) - GitHub
- [GHSA-55pq-j8p6-fr2h - jest-canvas-mock malware advisory](https://github.com/advisories/GHSA-55pq-j8p6-fr2h) - GitHub
- [GHSA-33m7-5xmx-p58p - mcp-echarts malware advisory](https://github.com/advisories/GHSA-33m7-5xmx-p58p) - GitHub
- [GHSA-2f6m-69ww-37wv - mcp-mermaid malware advisory](https://github.com/advisories/GHSA-2f6m-69ww-37wv) - GitHub
- [GHSA-g36c-rqq5-749v - ai-figure malware advisory](https://github.com/advisories/GHSA-g36c-rqq5-749v) - GitHub
- [GHSA-v2mr-5wmj-q99m - gantt-for-react malware advisory](https://github.com/advisories/GHSA-v2mr-5wmj-q99m) - GitHub
- [GHSA-8xch-qgqv-h8fh - amapcn malware advisory](https://github.com/advisories/GHSA-8xch-qgqv-h8fh) - GitHub
- [GHSA-qj5h-p6mj-66pf - @cap-js/openapi malware advisory](https://github.com/advisories/GHSA-qj5h-p6mj-66pf) - GitHub
- [GHSA-9frp-9f8j-wj97 - @webapp-next/store malware advisory](https://github.com/advisories/GHSA-9frp-9f8j-wj97) - GitHub
- [GHSA-4fqj-2fv5-gj83 - @design-system-coopeuch/web malware advisory](https://github.com/advisories/GHSA-4fqj-2fv5-gj83) - GitHub
- [GHSA-2fqh-pwxg-9x86 - @pelmnaads/naads-common-logger malware advisory](https://github.com/advisories/GHSA-2fqh-pwxg-9x86) - GitHub
- [GHSA-wfj4-qhgr-q7wq - bui-react-10components malware advisory](https://github.com/advisories/GHSA-wfj4-qhgr-q7wq) - GitHub
- [GHSA-gf4f-chpw-g8qh - @datatrain/passenger-v3 malware advisory](https://github.com/advisories/GHSA-gf4f-chpw-g8qh) - GitHub
- [GHSA-rqm7-j2qp-74f2 - identitysecuretokenserv malware advisory](https://github.com/advisories/GHSA-rqm7-j2qp-74f2) - GitHub
- [GHSA-cprr-jmxq-pj2p - paysafe-gbp-virtual-assistant-lib-fe malware advisory](https://github.com/advisories/GHSA-cprr-jmxq-pj2p) - GitHub
- [GHSA-5gr4-vr9v-phc3 - @convera/ui-shared malware advisory](https://github.com/advisories/GHSA-5gr4-vr9v-phc3) - GitHub
- [GHSA-cjw9-49j6-f3rw - @apps-home-dashboard/events malware advisory](https://github.com/advisories/GHSA-cjw9-49j6-f3rw) - GitHub
- [GHSA-rc69-pqv3-hw66 - apex-trading malware advisory](https://github.com/advisories/GHSA-rc69-pqv3-hw66) - GitHub
- [GHSA-h523-58g3-c5vg - apex-connector malware advisory](https://github.com/advisories/GHSA-h523-58g3-c5vg) - GitHub
- [GHSA-3hvw-w2fc-p2fg - @tc-core/campus-service malware advisory](https://github.com/advisories/GHSA-3hvw-w2fc-p2fg) - GitHub
- [GHSA-3x32-552f-fg4j - @citi-icg-158830/elemental-chameleon malware advisory](https://github.com/advisories/GHSA-3x32-552f-fg4j) - GitHub
- [GHSA-3v24-55c2-cpp9 - motion-forge-css malware advisory](https://github.com/advisories/GHSA-3v24-55c2-cpp9) - GitHub
- [GHSA-jxmp-2j7x-rvwp - sysbin malware advisory](https://github.com/advisories/GHSA-jxmp-2j7x-rvwp) - GitHub
- [GHSA-vqg5-mfj2-mmrr - typography-stylecss malware advisory](https://github.com/advisories/GHSA-vqg5-mfj2-mmrr) - GitHub
- [GHSA-766p-9cxp-2xxh - vue-template-compiler-plugin malware advisory](https://github.com/advisories/GHSA-766p-9cxp-2xxh) - GitHub
- [GHSA-j3r8-fm75-pfq7 - env-threads malware advisory](https://github.com/advisories/GHSA-j3r8-fm75-pfq7) - GitHub
- [GHSA-97qj-8m4x-2m8j - chai-as-regulated malware advisory](https://github.com/advisories/GHSA-97qj-8m4x-2m8j) - GitHub
- [GHSA-fg76-6277-9c5c - cache-poisoning-pwn-demo malware advisory](https://github.com/advisories/GHSA-fg76-6277-9c5c) - GitHub
- [GHSA-pmr5-xc5h-jpmq - prettier-lint-lenz malware advisory](https://github.com/advisories/GHSA-pmr5-xc5h-jpmq) - GitHub
- [GHSA-wx62-h3rg-4284 - request-logger-canary malware advisory](https://github.com/advisories/GHSA-wx62-h3rg-4284) - GitHub
- [GHSA-jmvw-wxmr-926c - prisma-callback malware advisory](https://github.com/advisories/GHSA-jmvw-wxmr-926c) - GitHub
- [GHSA-3x98-842h-2764 - claude-code-base-action malware advisory](https://github.com/advisories/GHSA-3x98-842h-2764) - GitHub
- [GHSA-p6pp-223j-cq7j - node-ci-utils malware advisory](https://github.com/advisories/GHSA-p6pp-223j-cq7j) - GitHub
- [GHSA-7mhg-447r-w46p - hello-world-pkg-value-value-p malware advisory](https://github.com/advisories/GHSA-7mhg-447r-w46p) - GitHub

---

Canonical page: https://dependencywatch.io/incident/npm-2026-07-28-ghsa-malware-sweep
Markdown version: https://dependencywatch.io/incident/npm-2026-07-28-ghsa-malware-sweep.md
Site index for agents: https://dependencywatch.io/llms.txt
DependencyWatch.io is operated by Precursor Security (https://precursorsecurity.com).
