GitHub Advisory npm CWE-506 sweep - 40+ package 2026-08-05 batch (massive Tinkoff Bank / dolyame BNPL / bnpl-blocks / tramvai / statist enterprise-scope dep-confusion burst, plus `clawtrl-wallet` crypto stealer + `sextant-cli-darwin-arm64` platform-binary + `@lizhao1/memorax-code-internal` + `@cliphijack/santaclaude` Claude-themed clipboard hijack + `llm-interceptor` + `multi-acct` + `kepler`)
GHSA published 40+ npm CWE-506 advisories dated 2026-08-05 dominated by a massive Tinkoff Bank (Russian bank) enterprise-scope dep-confusion burst: tinkoff-*, dolyame-boxy-* (Tinkoff BNPL), bnpl-blocks-atom-*, tramvai-* (Tinkoff's open-source framework), bigops-*, sme.rko.* internal namespaces. Also clawtrl-wallet (crypto wallet stealer), @cliphijack/santaclaude (Claude-themed clipboard hijack), sextant-cli-darwin-arm64, @lizhao1/memorax-code-internal, llm-interceptor, multi-acct, kepler, express-dever, svelte-mapped-metrics, streak-math-calc, streak-calc-metrics, svelte-mapping-core, eslint-plugin-vitest-ts, tailwindcss-scrollbar-hide, express-rate-controller, @stageflight-testbed/a, @workoscalif/sudoku, trapp-check-logs, sme-foundation-frame-manager.
- Detected by
- GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · npm Security
- Also known as
- 2026-08-05 GHSA npm batch · Tinkoff Bank dep-confusion burst · Dolyame BNPL squat cluster · bnpl-blocks-atom cluster
- Ecosystems
- npm
- Packages tracked
- 42
What happened
On 2026-08-05, the GitHub Advisory Database published 40+ new npm CWE-506 (Embedded Malicious Code) advisories dominated by a massive coordinated dep-confusion probe against Tinkoff Bank (JSC Tinkoff, one of Russia's largest banks) and its adjacent BNPL / SME / open-source-framework namespaces.
Cluster A - Tinkoff Bank / dolyame BNPL / bnpl-blocks internal-namespace dep-confusion burst (25+ packages, 2026-08-05)
A precise dep-confusion probe against Tinkoff Bank internal engineering namespaces:
Sub-cluster A.1 - Dolyame BNPL (Tinkoff's "buy-now-pay-later" product)
| Package | Notes | |---|---| | dolyame-boxy-independent-bnpl-items | BNPL items component | | dolyame-boxy-independent-bnpl-info-slider | BNPL info slider | | dolyame-boxy-independent-bnpl-partners | BNPL partners list | | dolyame-boxy-independent-bnpl-search | BNPL search | | dolyame-boxy-independent-bnpl-picture-gallery | BNPL image gallery | | dolyame-boxy-fonts | Fonts bundle | | dolyame-boxy-desktop-bnpl-text-block | BNPL text block |
Sub-cluster A.2 - BNPL blocks atoms
| Package | Notes | |---|---| | bnpl-blocks-atom-bnpl-email-form | Email form | | bnpl-blocks-atom-bnpl-badge | Badge atom | | bnpl-blocks-atom-bnpl-dropdown | Dropdown atom | | bnpl-blocks-atom-bnpl-info-card | Info card atom | | bnpl-blocks-atom-bnpl-news-card | News card atom | | bnpl-blocks-atom-bnpl-integrations-breadcrumbs | Breadcrumbs | | bnpl-blocks-atom-bnpl-dolyame-button | Dolyame CTA button | | bnpl-blocks-atom-bnpl-action-card | Action card |
Sub-cluster A.3 - Tinkoff internal statist / SME / RKO client libraries
| Package | Notes | |---|---| | tinkoff-statist-browser-typed-client-itsa.candy.selfservicesupport.frontend.events | Statist browser event client | | tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events | SME RKO mobile-pay event client | | tinkoff-pfp-block-desktop-tabs | PFP block tabs | | tinkoff-volna-zustate | Volna zustate | | tramvai-module-feature-toggle | Tramvai (Tinkoff's open-source React framework) feature-toggle module | | sme-foundation-frame-manager | SME foundation | | bigops-auth | BigOps auth |
Sub-cluster A.4 - Test / probe / other Tinkoff-adjacent
| Package | Notes | |---|---| | vvvedernikov-test-another-test | Developer-named test probe | | trapp-check-logs | Trapp check logs | | @ikbal_fadilah_vanexa01/vanexa-agent | Vanexa agent variant | | @stageflight-testbed/a | Stageflight testbed |
The Cyrillic-transliteration name conventions (dolyame = Dolyame BNPL, sme.rko = SME / RKO cash management, volna = wave, tramvai = tram, vvvedernikov = a Russian surname pattern) plus the depth and breadth of internal-namespace coverage confirm this is a targeted operation against Tinkoff Bank's internal npm registry. The operator has clearly enumerated real Tinkoff internal package names from a leaked package manifest, an accidentally-public repo, or a scraped package.json from an internal Tinkoff project.
Any Tinkoff Bank developer with a misconfigured .npmrc scope precedence who ran npm install in the 2026-08-05 window could have resolved the malicious public versions instead of the internal legitimate ones. Given the specificity of the internal namespaces, the yield rate is likely high on any Tinkoff developer laptop or CI runner that hit the public registry for these names.
Cluster B - clawtrl-wallet crypto-wallet stealer (1 package, 2026-08-05)
| Package | Notes | |---|---| | clawtrl-wallet | Explicit crypto-wallet-drain naming |
Cluster C - @cliphijack/santaclaude Claude-themed clipboard hijack (1 package, 2026-08-05)
| Package | Notes | |---|---| | @cliphijack/santaclaude | Scope name telegraphs clipboard-hijack payload; Claude-themed package name for developer targeting |
Scope @cliphijack is an unusually direct payload-class signal - clipboard hijacking. Package name santaclaude is a Claude-themed mock/target aimed at developers searching for Claude Code utilities. Clipboard-hijack payloads typically monitor pbcopy/xclip/xsel output or hook browser clipboard events and replace cryptocurrency addresses with attacker-controlled addresses at paste time - so a developer copy-pasting a Bitcoin/Ethereum/Solana address to send funds ends up sending to the attacker's wallet instead. Any recent crypto transaction on a compromised host should be verified against the intended destination address.
Cluster D - Platform-binary + internal-code cluster (2 packages, 2026-08-05)
| Package | Notes | |---|---| | sextant-cli-darwin-arm64 | Apple Silicon platform-binary squat for a sextant-cli target | | @lizhao1/memorax-code-internal | Internal-code shape suggests dep-confusion probe against memorax org |
Cluster E - LLM / agent tooling (2 packages, 2026-08-05)
| Package | Notes | |---|---| | llm-interceptor | Generic LLM interceptor tool naming | | multi-acct | Multi-account tooling naming |
Cluster F - Framework / build-tool typosquats and misc long tail (2026-08-05)
svelte-mapped-metrics, streak-math-calc, streak-calc-metrics, svelte-mapping-core, eslint-plugin-vitest-ts, tailwindcss-scrollbar-hide, express-dever, express-rate-controller, kepler, @workoscalif/sudoku. Standard CWE-506 fully-compromised remediation applies.
Registry state
All packages yanked / security-replaced from npm during the 2026-08-05 takedown. Private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs BEFORE the takedown WILL keep serving the original versions.
Related tracked activity
- Tinkoff / dolyame / BNPL cluster continues into 2026-08-06 (see
npm-2026-08-06-ghsa-malware-sweepCluster H sub-list) - the operator is running a multi-day enterprise-namespace enumeration burst against Tinkoff. @cliphijack/santaclaudematches the pattern of prior clipboard-hijack cryptocurrency-address-swap tools catalogued across recent months.- No
threatActorfield set - GHSA advisories use OpenSSFMAL-2026-*identifiers only. The consistency and volume of the Tinkoff cluster is strong evidence of a single operator running a scripted enumeration campaign.
Affected packages (42)
- npm@cliphijack/santaclaude1.0.0
- npm@ikbal_fadilah_vanexa01/vanexa-agent1.0.0
- npm@lizhao1/memorax-code-internal1.0.0
- npm@stageflight-testbed/a1.0.0
- npm@workoscalif/sudoku1.0.0
- npmbigops-auth1.0.0
- npmbnpl-blocks-atom-bnpl-action-card1.0.0
- npmbnpl-blocks-atom-bnpl-badge1.0.0
- npmbnpl-blocks-atom-bnpl-dolyame-button1.0.0
- npmbnpl-blocks-atom-bnpl-dropdown1.0.0
- npmbnpl-blocks-atom-bnpl-email-form1.0.0
- npmbnpl-blocks-atom-bnpl-info-card1.0.0
- npmbnpl-blocks-atom-bnpl-integrations-breadcrumbs1.0.0
- npmbnpl-blocks-atom-bnpl-news-card1.0.0
- npmclawtrl-wallet1.0.0
- npmdolyame-boxy-desktop-bnpl-text-block1.0.0
- npmdolyame-boxy-fonts1.0.0
- npmdolyame-boxy-independent-bnpl-info-slider1.0.0
- npmdolyame-boxy-independent-bnpl-items1.0.0
- npmdolyame-boxy-independent-bnpl-partners1.0.0
- npmdolyame-boxy-independent-bnpl-picture-gallery1.0.0
- npmdolyame-boxy-independent-bnpl-search1.0.0
- npmeslint-plugin-vitest-ts1.0.0
- npmexpress-dever1.0.0
- npmexpress-rate-controller1.0.0
- npmkepler1.0.0
- npmllm-interceptor1.0.0
- npmmulti-acct1.0.0
- npmsextant-cli-darwin-arm641.0.0
- npmsme-foundation-frame-manager1.0.0
- npmstreak-calc-metrics1.0.0
- npmstreak-math-calc1.0.0
- npmsvelte-mapped-metrics1.0.0
- npmsvelte-mapping-core1.0.0
- npmtailwindcss-scrollbar-hide1.0.0
- npmtinkoff-pfp-block-desktop-tabs1.0.0
- npmtinkoff-statist-browser-typed-client-itsa.candy.selfservicesupport.frontend.events1.0.0
- npmtinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events1.0.0
- npmtinkoff-volna-zustate1.0.0
- npmtramvai-module-feature-toggle1.0.0
- npmtrapp-check-logs1.0.0
- npmvvvedernikov-test-another-test1.0.0
These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.
Impact
- Cluster A - Tinkoff Bank / dolyame BNPL / bnpl-blocks internal-namespace dep-confusion burst (25+ packages, 2026-08-05): a coordinated dep-confusion probe against Tinkoff Bank (JSC Tinkoff Bank, one of Russia's largest banks) internal package namespaces. Squats include:
dolyame-boxy-*(Dolyame is Tinkoff's BNPL "buy-now-pay-later" product),bnpl-blocks-atom-bnpl-*(BNPL React component atoms),tinkoff-statist-browser-typed-client-sme.rko.*(Tinkoff SME / RKO internal client libraries - RKO = Расчётно-Кассовое Обслуживание, cash-management for business accounts),tramvai-module-feature-toggle(Tramvai is Tinkoff's open-source React framework),sme-foundation-frame-manager,bigops-*. Any Tinkoff Bank developer whose local.npmrcor CI misconfigured the private registry preference could pull the malicious public versions - Cluster B -
clawtrl-walletcrypto-wallet stealer (1 package, 2026-08-05): explicit crypto-wallet-drain naming. Standard CWE-506 boilerplate applies but the name and single-version drop matches the profile of a targeted wallet-stealer package. Any host that installed should treat every crypto wallet on it as fully compromised - Cluster C -
@cliphijack/santaclaudeClaude-themed clipboard hijack (1 package, 2026-08-05): scope@cliphijacktelegraphs the payload class - clipboard hijacking. Thesantaclaudepackage name mocks Claude Code / Anthropic tooling, targeting developers searching for Claude-adjacent utilities. Clipboard hijack payloads typically replace cryptocurrency addresses copied to the clipboard with attacker-controlled addresses at paste time - Cluster D - Platform-binary + internal-code cluster (2 packages, 2026-08-05):
sextant-cli-darwin-arm64(Apple Silicon platform binary squat),@lizhao1/memorax-code-internal(internal-code package name shape suggests dep-confusion probe against amemoraxorg) - Cluster E - LLM / agent tooling (2 packages, 2026-08-05):
llm-interceptor,multi-acct- naming targets developers building LLM/AI tooling - Cluster F - Framework / build-tool typosquats (5+ packages, 2026-08-05):
svelte-mapped-metrics,streak-math-calc,streak-calc-metrics,svelte-mapping-core,eslint-plugin-vitest-ts,tailwindcss-scrollbar-hide,express-dever,express-rate-controller,vvvedernikov-test-another-test,trapp-check-logs,kepler,@ikbal_fadilah_vanexa01/vanexa-agent,@stageflight-testbed/a,@workoscalif/sudoku. Standard CWE-506 fully-compromised remediation applies - All packages yanked / security-replaced from npm during the 2026-08-05 takedown. Private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs BEFORE the takedown WILL keep serving the original versions
What to do
- 1Grep every lockfile (
package-lock.json,yarn.lock,pnpm-lock.yaml) for the full 2026-08-05 package list below - especially the Tinkoff / dolyame / bnpl-blocks / tramvai / sme.rko cluster - 2For Tinkoff Bank / Tinkoff ecosystem developers: this is a targeted enterprise-scope dep-confusion probe against your internal package namespaces. Audit
.npmrcand.yarnrcfiles across all developer laptops and CI runners to confirm the private Tinkoff registry is set as the primary source withalways-auth=true. Configure explicit@dolyame:registry,@tinkoff:registry, and@sme.rko:registrymappings if any exist. Add explicitoverridesblocks inpackage.jsonfor the specific package names above - 3For
clawtrl-walletmatches: treat as a crypto-wallet stealer incident - move every crypto wallet balance to a fresh seed on an isolated host, rotate all seed phrases - 4For
@cliphijack/santaclaudematches: check clipboard-related utilities that may have been auto-installed. Any recent cryptocurrency transaction where you copy-pasted the destination address should be verified against the intended address - clipboard-hijack payloads specifically swap crypto addresses at paste time - 5For
sextant-cli-darwin-arm64matches: platform-binary distribution packages usually resolve viaoptionalDependencies+ platform detection. Verify which realsextant-clipackage your build was trying to install; the operator is squatting the Apple Silicon variant - 6For all npm installs in CI, run with
--ignore-scriptsas defense-in-depth to prevent preinstall/postinstall payloads from executing - 7Verify none of the 2026-08-05 packages still resolves via your private mirror
References
- GitHubGHSA-jh2q-fjxj-2jrr - dolyame-boxy-independent-bnpl-items malware advisory (Tinkoff BNPL dep-confusion)github.com
- GitHubGHSA-fm7r-fg6q-669q - tinkoff-volna-zustate malware advisorygithub.com
- GitHubGHSA-x32c-hhrc-xrc7 - tramvai-module-feature-toggle malware advisory (Tinkoff Tramvai framework)github.com
- GitHubGHSA-2g3q-h5qx-j6f8 - bigops-auth malware advisory (Tinkoff BigOps namespace)github.com
- GitHubGHSA-fh5c-3w68-67m4 - clawtrl-wallet malware advisory (crypto wallet stealer)github.com
- GitHubGHSA-mfhm-5r65-895x - @cliphijack/santaclaude malware advisory (Claude-themed clipboard hijack)github.com
- GitHubGHSA-2qg7-5p3x-vr75 - sextant-cli-darwin-arm64 malware advisorygithub.com
- GitHubGHSA-6wxr-274h-wx32 - llm-interceptor malware advisorygithub.com
- GitHubGitHub Advisory Database - recent npm malware advisoriesgithub.com