Feed
CriticalPublished 31 Jul 2026Updated 1 Aug 202692 packages · 92 versions

GitHub Advisory npm CWE-506 sweep - 91-package 2026-07-30/07-31 batch (`@peptide-packets` biotech scope pair, socket.io/mongoose/passport typosquat burst, ethers.js/rlp/fs-extra impersonator kit, `nano-perf` postinstall daemon C2, late-07-31 MCP-namespace burst, `@0xlr` dep-confusion PoC scope, `@spending-behavior-ui`/`@finance-ui`/`@mplay-*`/`@sof-assistant-*` enterprise dep-confusion sweep, `rollup-plugin-polyfill-hold`/`-helper` pair, `paraglide-js@1.0.1` takeover-style drop)

Summary

GHSA published 91 npm CWE-506 advisories 2026-07-30–07-31: existing 25-pkg batch (@peptide-packets, socket.io/mongoose/passport typos, ethers/rlp/fs-extra, nano-perf C2) plus a late-07-31 66-pkg wave - MCP-namespace burst (13), @0xlr dep-confusion PoC scope (10), enterprise internal-scope dep-confusion sweep (15 scoped pkgs), broad unscoped typosquats (25), rollup-plugin-polyfill-hold/-helper pair, paraglide-js@1.0.1 takeover.

typosquatcrypto-wallet-draincredential-theftinfostealerdependency-confusionci-cd-compromiseobfuscation
Detected by
GitHub Advisory Database · npm Security
Also known as
2026-07-30/07-31 GHSA npm batch · @peptide-packets operator continuation · socket.io/mongoose/passport typosquat burst · ethers.js/rlp/fs-extra impersonator kit · late-07-31 MCP-namespace burst · @0xlr dep-confusion PoC scope · enterprise internal-scope dep-confusion sweep 2026-07-31 · paraglide-js 1.0.1 takeover
Ecosystems
npm
Packages tracked
92

What happened

On 2026-07-30 and 2026-07-31, the GitHub Advisory Database published 91 new npm CWE-506 (Embedded Malicious Code) advisories - 8 dated 2026-07-30 and 83 dated 2026-07-31. This module was originally catalogued with the first-25 subset visible at yesterday's ingest snapshot; the 2026-08-01 update adds the additional 66 late-07-31 packages that landed after the previous ingest ran, grouped into five new clusters E–I.

Clear operator-cluster structure across nine thematic groups plus a scatter of single-package RATs indicates a wave of coordinated multi-package campaigns rather than 91 unrelated typosquats. The late-07-31 wave in particular reads as a single burst of orchestrated dep-confusion / typosquat activity targeting: (a) the MCP-server namespace (Anthropic MCP tooling), (b) enterprise internal-scope namespaces at multiple large organisations, and (c) the modern SaaS-integration stack (Sentry / Prisma / Vercel Analytics / Stripe / Clerk / Supabase - via the @0xlr PoC scope).

Cluster A - @peptide-packets/* operator-continuation of @peptide-unit (2 packages, all >= 0, all 2026-07-31)

| Package | Notes | |---|---| | @peptide-packets/peptide-modify | identical name to @peptide-unit/peptide-modify (07-29) | | @peptide-packets/js-unimode | identical name to @peptide-unit/js-unimode (07-29) |

This is a direct operator continuation of the 2026-07-29 @peptide-unit pair catalogued in npm-2026-07-30-ghsa-malware-sweep Cluster C. The two package names - peptide-modify (a plausibly-domain-specific peptide-analysis tool) paired with the nonsense-name js-unimode - are identical between the two scopes. Two publishes 48h apart under different attacker-owned scopes with the same package-name pair is unambiguously the same operator continuing to enumerate the internal-library namespace of a peptide-analysis / biotech target. This is the second recurrence of a dep-confusion probe against the same biotech target namespace - treat every @peptide-* scope as attacker-controlled until proven otherwise.

Cluster B - socket.io / mongoose / passport typosquat burst (8 packages, all >= 0, all 2026-07-31)

| Package | Legitimate target | |---|---| | socketi | socket.io | | soccketio | socket.io | | socktio | socket.io | | scketio | socket.io | | mongostose | mongoose | | moontose | mongoose | | passsport1 | passport | | passtpor | passport |

Same-day publish across 8 typosquats of three of the most-installed npm packages. Socket.IO / Mongoose / Passport together dominate the Node.js real-time / DB / auth stack for tutorial-driven Express codebases - the exact class of app where a paste-error from a tutorial or an ChatGPT-generated snippet delivers a lockfile hit. Coordinated broad-scatter typosquat kit rather than targeted operation.

Cluster C - ethers.js / rlp / fs-extra impersonator kit (8 packages, all >= 0, all 2026-07-30)

| Package | Legitimate target | |---|---| | ethe.json | ethers (v6 JSON-RPC provider) | | ethers.json | ethers (v6 JSON-RPC provider) | | ethersss | ethers | | rlp.git | rlp (Recursive-Length-Prefix, Ethereum wire encoding) | | rlp-master | rlp | | fsextrra | fs-extra | | fs-extra-master | fs-extra | | node-fs-extra-master | fs-extra |

The ethers + rlp co-occurrence points at Ethereum wallet / dApp developer targeting - rlp is a niche low-level Ethereum encoding library that only Ethereum-tooling developers pull in directly, and paired with ethers typosquats in the same batch it is a coordinated wallet-drainer kit. Same operator profile as the earlier 2026-06 polymarket-clob-math-vercel-loader and 2026-06 ts-einkle-ankle-wallet-cluster campaigns targeting Ethereum-tooling developer namespaces.

The fs-extra cluster in the same batch is more generic - fs-extra is a universal Node.js filesystem-utility (>50M weekly downloads) - but the -master suffix pattern (rlp-master, fs-extra-master, node-fs-extra-master) suggests all three came out of the same attacker-controlled fork-repository-naming template.

Cluster D - misc single-package RATs and exact-version drops (7 packages, 2026-07-31 unless noted)

| Package | Version | Notes | |---|---|---| | nano-perf | 2.2.0 | postinstall script launches daemon.js as detached unreferenced process for covert C2 - targeted exact-version drop | | redis-type-xyz | 1.10.6 | exact-version drop, Redis-type-annotation impersonation | | @dexwilt/node-fetch | 2.7.3 | attacker-scoped node-fetch typosquat - legitimate node-fetch@2.7.0 is the current v2 line so 2.7.3 pins to catch upgrade-path resolution | | @sudoughnym/enviro-demo | all | scoped "environment demo" - generic RAT boilerplate | | vcse | all | generic-name upload | | asdsafsadad | all | junk-name upload, likely researcher / red-team test | | asdsafsafdasdsaasdasda | all | junk-name upload, likely researcher / red-team test |

High-signal picks: nano-perf@2.2.0 is the standout - the GHSA advisory explicitly notes a postinstall script that launches daemon.js as a detached, unreferenced process, meaning a postinstall C2 handshake that survives the CI job that installed it. redis-type-xyz@1.10.6 and @dexwilt/node-fetch@2.7.3 are exact-version drops (rather than the more common all-versions typosquat) - the operator wants specific-version dependency-graph hits, not broad scatter.

The two asd… junk-name entries are almost certainly researcher / red-team test uploads left in the wild, but GHSA flagged them CWE-506 and they are catalogued here for completeness - a lockfile hit on either name is still an incident (either genuine malware or an unauthorised test).

Cluster E - MCP-namespace typosquat / impersonator wave (13 packages, all 2026-07-31, added 2026-08-01)

| Package | Notes | |---|---| | refbase-mcp | MCP-server namespace | | hit-mcp | MCP-server namespace | | mcp-server-boilerplate | high-signal generic-name land-grab | | iwomm-mcp | MCP-server namespace | | chaos-mcp | chaos-engineering + MCP fusion name | | gtm-mcp-auth | GTM (Google Tag Manager) MCP-auth impersonator | | sap-mcp-facilitator | SAP MCP integration namespace | | sap-mcp-config | SAP MCP integration namespace | | maximumsats-mcp | domain-specific MCP namespace | | kip-mcp-http | KIP MCP HTTP transport | | pm-claude-skills-mcp | Claude Skills MCP integration - targeted at Anthropic Claude Skills users | | smart-npv-mcp | domain-specific MCP namespace | | routerbase-mcp | MCP-server namespace |

Coordinated same-day burst against the Model Context Protocol namespace. Anthropic MCP tooling is the fastest-growing package category in npm and every mid-2026 GHSA batch has featured MCP-namespace typosquats. pm-claude-skills-mcp explicitly targets Claude Skills users - the operator is enumerating MCP-adjacent product-namespace real estate broadly. The generic mcp-server-boilerplate name is a namespace land-grab against a common project-scaffolding search phrase.

Cluster F - @0xlr/@404c3s4r scoped researcher/red-team PoC batch (11 packages, all 2026-07-31, added 2026-08-01)

| Package | Notes | |---|---| | @0xlr/dep-confusion-poc | smoking-gun name - literal PoC declaration | | @0xlr/sentry-web | Sentry error-tracking dep-confusion probe | | @0xlr/prisma-client-js | Prisma ORM dep-confusion probe | | @0xlr/vercel-analytics | Vercel Analytics dep-confusion probe | | @0xlr/stripe-checkout-js | Stripe SDK dep-confusion probe | | @0xlr/stripe-frontend | Stripe SDK dep-confusion probe | | @0xlr/clerk-auth | Clerk auth SDK dep-confusion probe | | @0xlr/supabase-db | Supabase DB SDK dep-confusion probe | | @0xlr/test-callback | generic test / callback probe | | @0xlr/question-types | generic probe | | @404c3s4r/lodash | lodash impersonator on separate attacker scope |

Every name in the @0xlr scope is a plausible enterprise dep-confusion target across the modern SaaS integration stack (Sentry / Prisma / Vercel Analytics / Stripe / Clerk / Supabase). The literal dep-confusion-poc sibling name outs this as almost-certainly a red-team / security-researcher enumeration exercise rather than a criminal operation - but GHSA flagged all 11 as CWE-506 and they are catalogued here for completeness. A lockfile hit is still an incident (either genuine malware or an unauthorised researcher upload with the same on-install exfil footprint), and the naming pattern is a useful lesson in how the enterprise-integration stack namespace is enumerable.

Cluster G - enterprise internal-scope dep-confusion sweep (15 packages, all 2026-07-31, added 2026-08-01)

| Package | Notes | |---|---| | @spending-behavior-ui/widget-insights | fintech-analytics scope | | @spending-behavior-ui/cashflow-widget | fintech-analytics scope | | @finance-ui/finance-view | fintech scope | | @finance-ui/snackbar-ifpe | fintech scope (IFPE = Instituición de Fondos de Pago Electrónico - Mexican fintech regulator) | | @nordic-dev/linting-tools | Nordic-region dev tooling scope | | @fuji-web-components/maps | Fuji web-components scope | | @meli-testing/jest-react | MercadoLibre (meli) testing scope | | @sw-commons-components/message-upsell | "sw" internal scope | | @mplay-core-lib/utilities | mplay- scope, possibly a media-player enterprise | | @mplay-frontend-ui/link | mplay- scope | | @global-theme/context | design-system scope | | @one-chat/react | chat product scope | | @sof-assistant-fe-lib/vertical-faqs | SoF assistant frontend scope | | @mp-op-ss-front-lib/tracks | mp-op-ss internal scope | | @cr-invested-ui-components/chart | Crédito Real / CR-Invested UI scope |

All 15 packages follow the canonical @<internal-org-scope>/<internal-package-name> dep-confusion probe pattern. The scope-name distinctness (5–10 different enterprises implied) means this is a broad enumeration campaign against multiple large orgs - the attacker publishes plausible internal-package-name shape into the public npm scope namespace on the bet that at least one target org has misconfigured .npmrc always-auth + scope-to-registry mapping. The @finance-ui/snackbar-ifpe name (IFPE is a Mexican fintech regulator) and @meli-testing/jest-react (MercadoLibre) suggest a Latin-American fintech / marketplace target concentration in this batch.

Cluster H - broad-scatter unscoped dep-confusion / typosquats (25 packages, all 2026-07-31, added 2026-08-01)

| Package | Notes | |---|---| | paraglide-js (1.0.1) | typosquat / squat against the legit paraglide-js i18n library - 1.0.1 version pin catches tutorial / example refs | | create-remotion | Remotion video-tooling namespace (create-* scaffold-name land-grab) | | capacitor-assets | Capacitor mobile-tooling namespace (legit @capacitor/assets exists) | | fast-csv-helper | fast-csv typosquat (dominant CSV parser, 4M weekly downloads) | | vite-tsconfig-svg / vite-config-svg / react-hot-svg | Vite plugin / React tooling namespace | | polyprompt, goldenflow-js, install-native-host, ai-backup-script, iac-scanner | generic-sounding tool names | | eth-bridge, kelly-stake | crypto-adjacent generic names | | frontend-regulations, metrics-ui, sso-users-detection, notifications-broadcast, portway, allurectl, adpanel-core, hazmat-cfr, attio-discover | enterprise-app-sounding internal-name shape | | community-published, process-status-widget, polylabel-web-lib | misc |

This unscoped subset is the wide-net counterpart to Cluster G - same operator pattern (plausible internal package names) but on the unscoped part of the npm namespace where any org that pushed internal libraries without scoping is exposed. paraglide-js@1.0.1 is a namespace-adjacent takeover attempt on the legitimate paraglide-js i18n library.

Cluster I - rollup-plugin-polyfill-* pair (2 packages, both 2026-07-31, added 2026-08-01)

| Package | Notes | |---|---| | rollup-plugin-polyfill-hold | rollup-plugin-polyfill-* namespace | | rollup-plugin-polyfill-helper | rollup-plugin-polyfill-* namespace |

Echoes the earlier npm-2026-07-03-jfrog-lazarus-rollup-polyfill-ottercookie DPRK Lazarus / OtterCookie campaign that targeted the same rollup-plugin-polyfill-* naming template. These two 07-31 entries carry only the generic CWE-506 boilerplate with no explicit actor attribution - treat as adjacent to the earlier Lazarus wave until a researcher writeup (JFrog / ReversingLabs / Socket / Wiz) explicitly attributes.

Registry state

All 91 packages security-replaced during the 2026-07-30 / 07-31 batch. Original version tarballs are no longer resolvable on the public registry, but private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs BEFORE the takedown WILL keep serving the original versions.

Related tracked activity

  • Cluster A directly extends the 07-29 @peptide-unit/* pair catalogued in npm-2026-07-30-ghsa-malware-sweep Cluster C - same operator, new scope.
  • Cluster C extends the operator space around npm-2026-07-08-injectivelabs-sdk-ts-crypto-wallet-drain, npm-2026-06-27-ts-einkle-ankle-wallet-cluster, and npm-2026-06-27-polymarket-clob-math-vercel-loader - all targeting Ethereum-tooling developer namespaces.
  • nano-perf@2.2.0 postinstall-daemon pattern echoes npm-2026-06-18-nastyc2-rust-implant-droppers and the earlier npm-2026-04-15-kindo-selfbot-xworm postinstall-C2 handshake patterns.
  • Cluster E (MCP-namespace burst) extends the mid-2026 MCP-typosquat trend - see npm-2026-07-30-ghsa-malware-sweep and multi-2026-04-29-promptmink-validate-sdk. Companion PyPI-side MCP activity in pypi-2026-07-31-ghsa-malware-sweep Cluster C (mcp-search-server).
  • Cluster G (internal-scope dep-confusion) extends the same operator pattern catalogued in npm-2026-06-29-internal-scope-dep-confusion-cluster and pypi-2026-07-21-ghsa-mass-backfill.
  • Cluster I (rollup-plugin-polyfill-* pair) is a plausible extension of npm-2026-07-03-jfrog-lazarus-rollup-polyfill-ottercookie (DPRK Lazarus / OtterCookie), pending explicit vendor attribution.
  • No threatActor field is set - GHSA advisories in this batch use only the CWE-506 boilerplate with no named actor attribution. Cluster F reads as a red-team/researcher exercise but is unattributed.

Affected packages (92)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • Any host that installed any of the 91 npm packages listed below should be treated as fully compromised - every GHSA record uses the CWE-506 boilerplate: "any computer that has this package installed or running should be considered fully compromised - rotate all secrets from a different computer" - and no patched version exists
  • *Cluster A - `@peptide-packets/ biotech scope pair, operator-continuation of @peptide-unit** (2 packages, all >= 0, all 2026-07-31): @peptide-packets/peptide-modify, @peptide-packets/js-unimode. These are **identical siblings** to the 2026-07-29 @peptide-unit/peptide-modify + @peptide-unit/js-unimode pair catalogued in npm-2026-07-30-ghsa-malware-sweep - same nonsense js-unimode paired with same peptide-modify` name, but under a new attacker-controlled scope. Two publishes 48h apart under different scopes with the same package-name pair is unambiguously the same operator continuing to enumerate the internal-library namespace of a peptide-analysis / biotech target
  • Cluster B - socket.io / mongoose / passport typosquat burst (8 packages, all >= 0, all 2026-07-31): socketi, soccketio, socktio, scketio (socket.io typos), mongostose, moontose (mongoose typos), passsport1, passtpor (passport typos). Same-day publish across 8 typosquats of three of the most-installed npm packages (Socket.IO >4M weekly, Mongoose >3M weekly, Passport >2M weekly) - coordinated broad-scatter typosquat kit rather than targeted operation
  • Cluster C - ethers.js / rlp / fs-extra impersonator kit (8 packages, all >= 0, all 2026-07-30): ethe.json, ethers.json, ethersss (ethers typos, Ethereum wallet interaction library), rlp.git, rlp-master (rlp typos - Recursive-Length-Prefix, Ethereum wire-format encoding), fsextrra, fs-extra-master, node-fs-extra-master (fs-extra typos). The ethers + rlp co-occurrence points at Ethereum wallet / dApp developer targeting - same operator profile as the 07-31 socket.io burst and prior @ts-einkle-ankle-wallet-cluster / polymarket-clob-math-vercel-loader campaigns
  • Cluster D - misc single-package RATs and exact-version drops (7 packages, mostly 2026-07-31): nano-perf@2.2.0 (postinstall script launches daemon.js as detached unreferenced process for covert C2 - targeted exact-version drop), redis-type-xyz@1.10.6 (exact-version drop, Redis-type-annotation impersonation), @dexwilt/node-fetch@2.7.3 (attacker-scoped node-fetch typosquat - legitimate node-fetch@2.7.0 is the current v2 line so 2.7.3 pins to catch upgrade-path resolution), @sudoughnym/enviro-demo, vcse, plus two obvious junk-name uploads (asdsafsadad, asdsafsafdasdsaasdasda - likely researcher / red-team test uploads, but GHSA flagged malware so catalogued for completeness)
  • Cluster E - MCP-namespace typosquat / impersonator wave (added 2026-08-01) (13 packages, all 2026-07-31): refbase-mcp, hit-mcp, mcp-server-boilerplate, iwomm-mcp, chaos-mcp, gtm-mcp-auth, sap-mcp-facilitator, maximumsats-mcp, sap-mcp-config, kip-mcp-http, pm-claude-skills-mcp, smart-npv-mcp, routerbase-mcp. Coordinated same-day burst against the Model Context Protocol namespace - Anthropic MCP-server tooling is the fastest-growing package category in npm and every mid-2026 GHSA batch has featured MCP typosquats. pm-claude-skills-mcp explicitly targets Claude-Skills-namespace developer workflows
  • Cluster F - @0xlr/@404c3s4r scoped researcher/red-team PoC batch (added 2026-08-01) (11 packages, all 2026-07-31): @0xlr/dep-confusion-poc (name is the smoking-gun - literal "PoC" declaration), @0xlr/sentry-web, @0xlr/prisma-client-js, @0xlr/vercel-analytics, @0xlr/stripe-checkout-js, @0xlr/test-callback, @0xlr/clerk-auth, @0xlr/question-types, @0xlr/stripe-frontend, @0xlr/supabase-db, @404c3s4r/lodash. Every name in the @0xlr scope is a plausible enterprise dep-confusion target (Sentry / Prisma / Vercel Analytics / Stripe / Clerk / Supabase - the modern SaaS stack) - this reads as a red-team / security-researcher enumeration exercise, but GHSA flagged all 11 as CWE-506 and they are catalogued for completeness. A lockfile hit is still an incident (either genuine malware or an unauthorised researcher upload)
  • Cluster G - enterprise internal-scope dep-confusion sweep (added 2026-08-01) (15 packages, all 2026-07-31): @spending-behavior-ui/widget-insights, @spending-behavior-ui/cashflow-widget, @finance-ui/finance-view, @finance-ui/snackbar-ifpe (fintech UI namespace - Mercado Pago / Nubank / similar Latin-American fintech target profile), @nordic-dev/linting-tools, @fuji-web-components/maps, @meli-testing/jest-react (MercadoLibre), @sw-commons-components/message-upsell, @mplay-core-lib/utilities, @mplay-frontend-ui/link, @global-theme/context, @one-chat/react, @sof-assistant-fe-lib/vertical-faqs, @mp-op-ss-front-lib/tracks, @cr-invested-ui-components/chart. All 15 are @<internal-org-scope>/<internal-package-name> shape - canonical dep-confusion probe pattern targeting the internal-library namespaces of 5–10 large enterprises (based on the scope-name distinctness). Any lockfile hit means the target org's private-scope resolution fell through to the public registry
  • Cluster H - broad-scatter unscoped dep-confusion / typosquats (added 2026-08-01) (25 packages, all 2026-07-31): paraglide-js@1.0.1 (typosquat of the legitimate paraglide-js i18n library - the 1.0.1 version pin is designed to land on tutorials or examples referencing v1), create-remotion (Remotion video-tooling namespace), capacitor-assets (Capacitor mobile-tooling namespace - legit @capacitor/assets exists), paraglide-js, fast-csv-helper (fast-csv typosquat), vite-tsconfig-svg, react-hot-svg, vite-config-svg (vite plugin-namespace typosquats), polyprompt, goldenflow-js, install-native-host, ai-backup-script, iac-scanner, eth-bridge, kelly-stake, frontend-regulations, metrics-ui, sso-users-detection, notifications-broadcast, portway, allurectl (Allure testing tooling), adpanel-core, hazmat-cfr, attio-discover, community-published, process-status-widget, polylabel-web-lib
  • *Cluster I - `rollup-plugin-polyfill- pair (added 2026-08-01)** (2 packages, both 2026-07-31): rollup-plugin-polyfill-hold, rollup-plugin-polyfill-helper. Echoes the earlier npm-2026-07-03-jfrog-lazarus-rollup-polyfill-ottercookie DPRK campaign - same rollup-plugin-polyfill-*` naming template used by DPRK Lazarus / OtterCookie operators, though these two carry only the generic CWE-506 boilerplate with no explicit actor attribution. Treat as adjacent to the earlier Lazarus rollup-polyfill wave until researcher writeups confirm otherwise
  • None of the 91 packages retain original tarballs on the public npm registry - all replaced with security sentinels during takedown. Private registry mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs BEFORE the takedown WILL keep serving the original versions

What to do

  1. 1Grep every lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml) for each name in the packages map below. Any match is a supply-chain incident: rotate every credential the build runner could reach and re-image the build host
  2. 2Cluster C (ethers.js / rlp / fs-extra kit): any hit on any of the 8 packages on a host that runs Ethereum wallet software, dApp code, or holds signing keys: treat as full crypto-wallet-compromise event. Move funds via a clean device BEFORE attempting rotation. Rotate every dev-wallet seed phrase, MetaMask account, and hardware-wallet PIN accessible from the affected host
  3. 3Cluster B (socket.io/mongoose/passport typosquat burst): fix the misspelling in package.json before re-installing - a typo hit is often a paste error from a tutorial or ChatGPT-generated snippet. Rotate any session-signing secrets, MongoDB connection strings, and OAuth client secrets that the compromised app touched
  4. 4*Cluster A (`@peptide-packets/)**: configure .npmrc scope-to-registry mapping so private-scope resolution never falls through to the public registry. Also add @peptide-unit` to the same allow-list - same operator, same target namespace
  5. 5Cluster D single-package hits: nano-perf@2.2.0 and redis-type-xyz@1.10.6 are exact-version drops - targeted rather than broad scatter. If either hits your lockfile, treat the build host as compromised and audit outbound network for the daemon.js C2 channel. @dexwilt/node-fetch@2.7.3 targets developers on the v2 line - pin to the legitimate node-fetch@^2.7.0 from github.com/node-fetch/node-fetch and verify the resolved integrity hash
  6. 6For projects using postinstall-scripting packages, run npm install --ignore-scripts in CI as defense-in-depth - nano-perf@2.2.0 demonstrates that a postinstall-launched detached daemon can survive the CI job that installed it
  7. 7Clusters E–I (added 2026-08-01): for MCP-namespace typosquats (Cluster E) - audit any developer machine running Model-Context-Protocol server tooling and pin MCP dependencies via overrides in package.json to trusted registry paths. For @0xlr/@404c3s4r (Cluster F) - treat any hit as an incident regardless of researcher-vs-genuine origin; unauthorised researcher uploads still exfiltrate on install. For internal-scope dep-confusion (Cluster G) - every organisation should audit their .npmrc always-auth + scope-to-registry mappings for @spending-behavior-ui, @finance-ui, @mplay-*, @sof-assistant-*, @sw-commons-components, @meli-testing, @mp-op-ss-front-lib, @cr-invested-ui-components - a public-registry fall-through resolves the attacker package. For unscoped Cluster H - the paraglide-js@1.0.1 drop is a takeover-style attempt on a namespace close to the legit paraglide-js library; verify the resolved integrity hash matches the real project's current registry entry
  8. 8Verify none of the 91 listed packages still resolves via your private mirror - internal Artifactory / Nexus / Verdaccio instances routinely cache tarballs and will keep serving the original versions after the public yank

References

npm-2026-07-31-ghsa-malware-sweep