GitHub Advisory npm CWE-506 sweep - 2026-08-12 batch (Web3 typosquat webhook.site ring day-2 `permit2`+`camelot-ammv2-*`+`boring-vault`+`augustdigital-sdk`+`upshift-*`, Ethereum-RPC-C2 `envpack-conf`+`tailwind-form-templates` XOR-encrypted second-stage on blockchain, `svelte-kit-vim`+`kit-map-vim` map-streak-kit day-4 continuation, `sui-gql`+`bcs-compact` Sui `@mysten/*` typosquat continuation, ~50-package `@years17/18/19/20/*` n8n-nodes-utils-helper red-team SSH-backdoor mass drop, `internallib_v756`/`v392` bare `/dev/tcp/10.0.74.63/4444` reverse shell, `mcp-util-helpers` webhook.site R-shell channel, `passkeys-react` Burp Collaborator OAST recon, `bb-twl-k7x2` Twilio-internal dep-confusion, `@telekom-ods/react-ui-kit` Deutsche Telekom internal-scope, `verify-cli`+`@assetshop/verify-cli` OAST recon pair, `dakumangalsingh` Java-Robot RAT with jpackage wrapper, boilerplate CWE-506 mass npm flood ~100 packages)
~160 npm CWE-506 advisories published 2026-08-12. Headline: Web3 typosquat webhook.site ring day-2 (permit2, camelot-ammv2-core/periphery, boring-vault, augustdigital-sdk, upshift-finance/config) with identical env/wallet-keystore exfil TTP as the 08-11 OpenZeppelin/Aerodrome ring; Ethereum-RPC-C2 pair (envpack-conf, tailwind-form-templates) fetching XOR-encrypted second-stage from blockchain via wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a; and a *~50-package `@years17/18/19/20/` red-team n8n mass drop** installing pwn@kali SSH backdoors.
- Detected by
- GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · npm Security · amazon-inspector · kam193 bad-packages
- Also known as
- 2026-08-12 GHSA npm batch · Web3 webhook.site typosquat ring day-2 · Ethereum-RPC-C2 register · map-streak-kit family day-4 · years17-20 n8n red-team mass drop · mssjeep843 Web3 cluster
- Ecosystems
- npm
- Packages tracked
- 159
What happened
On 2026-08-12, the GitHub Advisory Database published ~160 new npm CWE-506 (Embedded Malicious Code) advisories - the largest single-day batch in the sweep-tracking window since the 2026-05-11 TanStack Mini Shai-Hulud burst. The shape is a mix of high-conviction targeted operations (Web3 typosquat continuations, Deutsche Telekom compromise, Twilio dep-confusion probe, n8n red-team mass drop) and a very large boilerplate CWE-506 flood.
Cluster A - Web3 typosquat webhook.site credential-theft ring day-2 (7 packages, same-operator continuation of 2026-08-11 Cluster A)
| Package | Versions | GHSA | Impersonated target | |---|---|---|---| | permit2 | 1.0.0, 1.0.1 | GHSA-5hx7-m92r-hc5c | Uniswap Permit2 SDK (@uniswap/permit2-sdk) | | camelot-ammv2-core | 1.0.0, 1.1.0, 1.1.1 | GHSA-j6vj-qx8g-mv2c | Camelot DEX AMM v2 core contracts | | camelot-ammv2-periphery | 1.0.0, 1.1.0, 1.1.1 | GHSA-m3cv-6763-2mrv | Camelot DEX AMM v2 periphery | | boring-vault | 1.0.0, 1.1.0, 1.1.1 | GHSA-2hm3-fxxw-fwgw | Veda BoringVault Solidity framework | | augustdigital-sdk | 8.20.1 | GHSA-pfx4-g5xh-hpf6 | @augustdigital/sdk | | upshift-finance | 1.0.0 | GHSA-p98f-6986-rf79 | August Digital / Upshift Finance | | upshift-config | <=0.5.14 | GHSA-75gq-p797-7w4c | August Digital / Upshift config |
Sub-ring A1 - permit2 ships the identical webhook.site payload as the 08-11 OpenZeppelin/Aerodrome/Euler ring: preinstall + postinstall both trigger, env-var filter for KEY/TOKEN/SECRET/PRIVATE/MNEMONIC/AWS/WALLET, reads ~/.aws/, ~/.ssh/, ~/.kube/, ~/.docker/, ~/.netrc, ~/.npmrc, blockchain keystores under Solana / Sui / Foundry / Anchor, detached child process with randomised delay + sandbox-evasion hostname checks, POST to hardcoded webhook.site endpoint. Same operator or coordinated with the 08-11 ring.
Sub-ring A2 - mssjeep843 npm account (published camelot-ammv2-core, camelot-ammv2-periphery, boring-vault plus two related PyPI packages the 08-11 PyPI sweep picked up): v1.0.0 does env-var + wallet-keystore + .npmrc/.gitconfig exfil to a shared webhook, v1.1.0 escalates to reading full file contents up to 4000 bytes from .aws/credentials, .ssh/id_rsa/id_ed25519, and Solana/Anchor/NEAR/Sui wallet keystores plus regex-scans local .env files for BEARER, API, INFURA, ALCHEMY, PRIVATE_KEY patterns.
Sub-ring A3 - awugochogabriel@gmail.com freemail account (published augustdigital-sdk, upshift-finance, upshift-config within seconds of each other on 2026-08-10, disclosed 08-12): brand-hijack repack of @augustdigital/sdk with a hidden postinstall that beacons to build-metrics-collector.cdn-ops-health.workers.dev/npm-install/ disguised as CDN health metrics. Payload transmits hostname, username, cwd, package details, and ISO timestamp - no secondary credential-harvest identified. The Cloudflare Workers cover makes the exfil traffic look like ordinary CDN telemetry.
All three sub-rings targeting DeFi / Solidity SDKs on the same day continue the sustained typosquat pressure against DeFi vendor namespaces documented in the 08-11 sweep. Expect further sibling drops in the next 24-72h.
Cluster B - Ethereum-RPC-C2 pair with XOR-encrypted second-stage on blockchain (2 packages)
| Package | Versions | GHSA | Impersonated target | Wallet address | |---|---|---|---|---| | envpack-conf | 1.0.1 | GHSA-fw27-f4gv-qw69 | Sindre Sorhus pkg-conf | 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a | | tailwind-form-templates | <=0.7.4 | GHSA-f88v-2vrh-8v5c | @tailwindcss/forms | 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a |
Both packages query public Ethereum RPC endpoints and blockchain explorers at import time to retrieve attacker-controlled instructions from transactions the operator sent from wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a. The transaction data decodes to two IPv4 addresses; the malware then fetches an XOR-encrypted second-stage payload from <IP>/0x/cls with custom headers, decrypts it, and executes it via eval() + spawned Node child processes. Strings are Unicode-escaped (\uXXXX) throughout.
The operator can rotate the second-stage IPs silently by publishing new transactions without republishing the package - taking down the two currently-staged IPs does not neutralise the loader. envpack-conf typosquats Sindre Sorhus's pkg-conf (byline "Sinde Sorus" - one letter off in first and last name); tailwind-form-templates shadows @tailwindcss/forms. Same wallet address across both packages - one operator staging both.
Cluster C - svelte-kit-vim + kit-map-vim map-streak-kit family day-4 continuation (2 packages)
| Package | Versions | GHSA | |---|---|---| | svelte-kit-vim | 1.0.0 | GHSA-mpgw-38v3-8q5v | | kit-map-vim | 1.0.0 | GHSA-hg96-r46x-6f4w |
Boilerplate CWE-506 on both. Fourth consecutive daily drop - the register is now <framework>-kit-<editor> and kit-map-<editor>, permuting the 08-11 register (<framework>-<editor>-kit, kit-<editor>-map) which itself permuted the 08-10 register (<framework>-kit-<streak>, kit-<map>-<streak>) and the 08-08 base (map-streak-kit, streak-map-kit, svelte-streak-kit, svelte-kit-cache). Treat as sibling drops of the 08-08 Linux implant + systemd persistence + SSH-key exfil family until Socket/OpenSSF post differentiated samples.
Cluster D - sui-gql + bcs-compact Sui blockchain typosquat continuation (2 packages)
| Package | Versions | GHSA | Typosquats | |---|---|---|---| | sui-gql | >=0 | GHSA-4958-mj82-77pj | @mysten/sui/graphql/client | | bcs-compact | >=0 | GHSA-xr26-x39h-746w | @mysten/bcs |
Boilerplate CWE-506 - short-form variant of the 08-11 sui-gql-client/sui-bcs-codec pair. Same-operator second-day drop staging both long-form and short-form names for each Sui module.
Cluster E - @years17/* + @years18/* + @years19/* + @years20/* n8n-nodes-utils-helper red-team mass drop (~50 packages)
Approximately 50 packages across four scopes (@years17, @years18, @years19, @years20) with suffixes -a through -y plus -helper-utils. This is a single-operator red-team mass drop targeting n8n community node maintainers - all share the same exfil endpoint (https://jasabersama.id/portfolio-data.php) and the same triple-execution model:
- Postinstall writes
/tmp/pwned.txtand executes reconnaissance (id,hostname,git --version,node --version,n8ninstall-path checks,~/.n8n/directory contents). - Module-load-time payload runs the same recon and writes
/tmp/n8n_pwned.txt- the advisory comment on@years17/n8n-nodes-helper-utilsexplicitly notes execution happens "inside n8n's main process with no sandbox". - Workflow execute() on the exported node class runs
id,hostname,uname -a, and directory listings, returning results markedpwned: true.
Specific samples widen the impact:
@years17/n8n-nodes-utils-helper-eappends the attacker SSH key labeledpwn@kalito/home/ubuntu/.ssh/authorized_keys, runssudo -n -lto enumerate passwordless sudo capability, checksdocker ps, and registers aPwnNodeclass inside n8n that runs additional commands and returnspwned: true.@years20/n8n-nodes-utils-helper-hbase64-encodes recon output and beacons tojasabersama.id/portfolio-data.phpwith TLS validation disabled; URL parameters include a shell pipeline suggesting command-and-control tasking.
The scale (~50 packages) and the identical infrastructure make this a coordinated red-team engagement (or a red-team-tool-based attacker campaign) against organisations using n8n community nodes at scale. The pwn@kali SSH key label plus /tmp/pwned.txt//tmp/n8n_pwned.txt markers plus PwnNode class name are consistent with a Kali-hosted red-team engagement.
Cluster F - internallib_v756 + internallib_v392 bare /dev/tcp/10.0.74.63/4444 reverse-shell dep-confusion (2 packages, sibling of 08-11 internallib_v164)
| Package | Versions | GHSA | C2 | |---|---|---|---| | internallib_v756 | <=1.0.7 | GHSA-49mj-627r-8grx (+ GHSA-933g-5588-v5hp) | 10.0.74.63:4444 via /dev/tcp | | internallib_v392 | >=0 | GHSA-j9qq-rx28-vcjh | boilerplate (sibling) |
internallib_v756 executes at module-load-time via execSync an interactive bash shell to hardcoded RFC1918 address 10.0.74.63:4444 via /dev/tcp - fires with no conditional logic on every require. internallib_v392 is the boilerplate sibling. Same operator as the 08-11 internallib_v164 - naming register internallib_v<3-digit random> continues.
Cluster G - mcp-util-helpers webhook.site R-shell channel (1 package)
| Package | Versions | GHSA | C2 channel | |---|---|---|---| | mcp-util-helpers | 1.0.0 | GHSA-76x8-h996-qvxr | webhook.site (bidirectional) |
Preinstall runs scripts/check-env.js: collects whoami/id/uname + ip route / ss -tlnp / netstat / running processes / Docker containers + credential env vars + ~/.ssh/ contents + /etc/passwd//etc/hosts, POSTs to webhook.site, then parses the response body for cmd or url fields and executes attacker-supplied shell commands or downloads and runs payloads to /tmp/.mcp-util-setup - a full command-and-control channel over the webhook response body. Naming targets the Model Context Protocol (MCP) tooling ecosystem.
Cluster H - passkeys-react Burp Collaborator OAST recon (1 package)
| Package | Versions | GHSA | Beacon | |---|---|---|---| | passkeys-react | 1.0.1 | GHSA-8rr9-mc57-cwmx | ltivq9rn7t7gkxho4o1micsk6bc20uoj.oastify.com |
Preinstall collects hostname, username, homedir, DNS servers, cwd, /etc/passwd, /etc/hosts; HTTPS-GETs to a Burp Collaborator subdomain. Naming targets the WebAuthn / passkey React ecosystem.
Cluster I - bb-twl-k7x2 Twilio-internal dep-confusion (1 package)
| Package | Versions | GHSA | Beacon | |---|---|---|---| | bb-twl-k7x2 | 1.0.0, 1.0.1 | GHSA-3ffh-ppq4-pgrx | http://whstool.brkd.no/cb53e6db-e043-4383-89e9-853c9088ee5d/ |
canary.js runs at install: os.hostname(), id, hostname -I, ip addr, ls /, ls -a $HOME, and getent hosts internal.twilio.com to probe internal-DNS resolvability. Searches for _auth/_authToken/password tokens in .npmrc across HOME/root/etc/parent, hits AWS instance metadata for IAM role info, exfils via HTTP GET query string over unencrypted HTTP. If your build host resolves internal.twilio.com and pulled this package, the operator now knows.
Cluster J - @telekom-ods/react-ui-kit Deutsche Telekom internal-scope compromise (1 package, 2 versions, /etc/shadow attempt)
| Package | Versions | GHSA | Beacon | |---|---|---|---| | @telekom-ods/react-ui-kit | 2.6.0, 2.6.9 | GHSA-7hwp-8qhg-wfmp | d9t83osijf9n1gb62e4gxfioysijywqww.oast.me |
Installation-hook shell command reads /etc/passwd, /etc/hosts, and conditionally /etc/shadow, embeds username+hostname in the callback URL, HTTPS-GETs to an oast.me subdomain. Publisher metadata matched legitimate prior releases - the advisory notes compromised maintainer account or supply-chain injection, not typosquat. @telekom-ods is a Deutsche Telekom Open Digital Solutions internal scope.
Cluster K - verify-cli + @assetshop/verify-cli dep-confusion recon pair (2 packages)
| Package | Versions | GHSA | Beacon | |---|---|---|---| | verify-cli | 99.0.0 | GHSA-3xrr-9gq8-rv8h | 5f8a1ed70fb7761d678agw9bucryyyyyb.oast.site | | @assetshop/verify-cli | 99.0.0, 99.0.1 | GHSA-9vm3-xhgh-q4pr | 5f8a1ed70fb7761d678agw9bapayyyyyb.oast.site |
verify-cli preinstall base64-encodes /etc/passwd, /etc/hosts, /etc/shadow + whoami/hostname/id, POSTs to OAST. @assetshop/verify-cli collects host metadata, HTTPS-GETs to OAST, and fires a DNS-fanout stub ${user}.${hostname}.assetshop-verify-cli.<oast-host>.
Cluster L - dakumangalsingh Java-Robot Windows RAT with jpackage wrapper (1 package, 3 versions)
| Package | Versions | GHSA | Payload | |---|---|---|---| | dakumangalsingh | 1.0.0, 1.0.1, 1.1.0 | GHSA-h2fc-hhv7-4596 | DakuMangalSingh.exe (jpackage) + virus.jar |
Postinstall auto-executes on Windows. virus.jar bundles Java-Robot screen capture, keystroke/mouse-input synthesis, host fingerprinting, HKCU+startup-shortcut persistence, and an anti-forensics cleanup batch. Same-operator sibling of the boilerplate dakumangalsingh_virus from 08-11 Cluster I.
Cluster M - Massive random-name / themed-name npm flood (~100+ boilerplate packages)
A single-day burst of ~100 packages with random-looking or thematically-clustered names. Random group: hgdvfuflnb, jkbnwsdf8, cvbniydplwe3, cvbmxiowkwqla6, csbcldfvivwfgd4, bmgki3g6fh3, and many more. Themed group: aviation (china_airlines), Taiwan (ms_aidc_com_tw), telecom (unitel3/unitel4, mobicommn, mobicwkgjmx), Chinese-name lures (yangming708/yangming8, kanyut, thundertiger, prezdentkxheiw), passport/ID lures (passport811, egypt0811, airdzticket). All carry boilerplate CWE-506 without differentiated behavioural analysis. Naming pattern suggests coordinated multi-target dep-confusion probes plus mass automated npm spam. Blast radius uncharacterised - treat as capable of the same credential-theft behaviour as the fully-analysed batch members.
Cluster N - @noxzacode/* + noxleys operator cluster (3 packages)
| Package | Versions | GHSA | |---|---|---| | @noxzacode/eslint-config | >=0 | GHSA-7x8x-h24p-92f4 | | @noxzacode/libsignal-node | >=0 | GHSA-7p3j-35rp-g3v5 | | noxleys | >=0 | GHSA-rch8-8p8v-23j7 |
Same-day publication implies one operator. libsignal-node is a Signal Protocol library typosquat; eslint-config is generic. Boilerplate CWE-506.
Cluster O - @bikli/* + bikli* operator cluster (5 packages)
| Package | Versions | GHSA | |---|---|---| | @bikli/bikli | >=0 | GHSA-jrmr-j9fg-c874 | | @bikli/cli | >=0 | GHSA-cc5p-hf7h-rrjh | | biklirouter | >=0 | GHSA-f5c6-4rpr-wjhp | | bikliwrapper | >=0 | GHSA-3qxv-77j4-mg7c | | biklimaster | >=0 | GHSA-pcfp-4v4q-w735 |
Single operator staging both scoped (@bikli/*) and unscoped (bikli*) forms same-day. Boilerplate CWE-506.
Registry state
All ~160 packages yanked or security-holding-replaced from npm during the 2026-08-12 takedown window. Private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs before takedown will keep serving the malicious versions.
Related tracked activity
- Web3 typosquat webhook.site register continuation: Cluster A is the second-day drop of the 08-11 Cluster A OpenZeppelin/Aerodrome/Euler ring. Same operator, targeting expands to Uniswap Permit2, Camelot AMM v2, Veda BoringVault, August Digital, Upshift Finance. Predicted 08-13/14/15 continuations targeting Compound, Aave, Morpho, Yearn, or Curve.
- Ethereum-RPC-C2 register: Cluster B is a new register using public Ethereum RPCs as a C2 rendezvous point via a hardcoded wallet address (
0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a). If further packages appear that fetch instructions from this wallet, they belong here. - map-streak-kit Linux implant family day-4: Cluster C is the fourth consecutive daily drop of the family established on 2026-08-08 and continued 08-10 and 08-11.
internallib_v<random>register: Cluster F continues 08-11internallib_v164. The 10.0.74.63:4444 RFC1918 C2 host implies a specific-network target rather than a broad campaign.- *Sui `@mysten/
typosquat register**: Cluster D continues [08-11sui-gql-client/sui-bcs-codec`](/incident/npm-2026-08-11-ghsa-malware-sweep). - Deutsche Telekom compromise (Cluster J): not previously seen in tracked data. Escalate at DT if you can - the advisory suggests maintainer-account or CI/CD compromise, not typosquat.
- Discovery credits:
OpenSSF malicious-packages,OpenSSF Package Analysis,npm Security,amazon-inspector,kam193 bad-packages. No named threat actor.
Affected packages (159)
- npm@assetshop/verify-cli99.0.099.0.1
- npm@bikli/bikli1.0.0
- npm@bikli/cli1.0.0
- npm@noxzacode/eslint-config1.0.0
- npm@noxzacode/libsignal-node1.0.0
- npm@telekom-ods/react-ui-kit2.6.02.6.9
- npm@years17/n8n-nodes-helper-utils1.0.01.0.11.0.21.0.31.0.41.0.51.0.6
- npm@years17/n8n-nodes-utils-helper1.0.0
- npm@years17/n8n-nodes-utils-helper-b1.0.0
- npm@years17/n8n-nodes-utils-helper-c1.0.0
- npm@years17/n8n-nodes-utils-helper-d1.0.0
- npm@years17/n8n-nodes-utils-helper-e1.0.0
- npm@years17/n8n-nodes-utils-helper-f1.0.0
- npm@years17/n8n-nodes-utils-helper-g1.0.0
- npm@years17/n8n-nodes-utils-helper-h1.0.0
- npm@years17/n8n-nodes-utils-helper-i1.0.0
- npm@years18/n8n-nodes-utils-helper-a1.0.0
- npm@years18/n8n-nodes-utils-helper-b1.0.0
- npm@years18/n8n-nodes-utils-helper-c1.0.0
- npm@years18/n8n-nodes-utils-helper-d1.0.0
- npm@years18/n8n-nodes-utils-helper-e1.0.0
- npm@years18/n8n-nodes-utils-helper-f1.0.0
- npm@years18/n8n-nodes-utils-helper-g1.0.0
- npm@years18/n8n-nodes-utils-helper-j1.0.0
- npm@years18/n8n-nodes-utils-helper-k1.0.0
- npm@years18/n8n-nodes-utils-helper-l1.0.0
- npm@years18/n8n-nodes-utils-helper-m1.0.0
- npm@years18/n8n-nodes-utils-helper-n1.0.0
- npm@years18/n8n-nodes-utils-helper-o1.0.0
- npm@years18/n8n-nodes-utils-helper-p1.0.0
- npm@years18/n8n-nodes-utils-helper-q1.0.0
- npm@years18/n8n-nodes-utils-helper-r1.0.0
- npm@years18/n8n-nodes-utils-helper-s1.0.0
- npm@years18/n8n-nodes-utils-helper-t1.0.0
- npm@years18/n8n-nodes-utils-helper-u1.0.0
- npm@years18/n8n-nodes-utils-helper-v1.0.0
- npm@years18/n8n-nodes-utils-helper-w1.0.0
- npm@years18/n8n-nodes-utils-helper-x1.0.0
- npm@years18/n8n-nodes-utils-helper-y1.0.0
- npm@years19/n8n-nodes-utils-helper-a1.0.0
- npm@years19/n8n-nodes-utils-helper-b1.0.0
- npm@years19/n8n-nodes-utils-helper-c1.0.0
- npm@years19/n8n-nodes-utils-helper-d1.0.0
- npm@years19/n8n-nodes-utils-helper-e1.0.0
- npm@years19/n8n-nodes-utils-helper-f1.0.0
- npm@years19/n8n-nodes-utils-helper-g1.0.0
- npm@years19/n8n-nodes-utils-helper-h1.0.0
- npm@years19/n8n-nodes-utils-helper-i1.0.0
- npm@years19/n8n-nodes-utils-helper-j1.0.0
- npm@years19/n8n-nodes-utils-helper-k1.0.0
- npm@years19/n8n-nodes-utils-helper-l1.0.0
- npm@years19/n8n-nodes-utils-helper-m1.0.0
- npm@years19/n8n-nodes-utils-helper-n1.0.0
- npm@years19/n8n-nodes-utils-helper-o1.0.0
- npm@years19/n8n-nodes-utils-helper-p1.0.0
- npm@years19/n8n-nodes-utils-helper-q1.0.0
- npm@years19/n8n-nodes-utils-helper-r1.0.0
- npm@years19/n8n-nodes-utils-helper-s1.0.0
- npm@years19/n8n-nodes-utils-helper-t1.0.0
- npm@years19/n8n-nodes-utils-helper-u1.0.0
- npm@years19/n8n-nodes-utils-helper-v1.0.0
- npm@years19/n8n-nodes-utils-helper-w1.0.0
- npm@years19/n8n-nodes-utils-helper-x1.0.0
- npm@years19/n8n-nodes-utils-helper-y1.0.0
- npm@years20/n8n-nodes-utils-helper-a1.0.0
- npm@years20/n8n-nodes-utils-helper-b1.0.0
- npm@years20/n8n-nodes-utils-helper-c1.0.0
- npm@years20/n8n-nodes-utils-helper-d1.0.0
- npm@years20/n8n-nodes-utils-helper-e1.0.0
- npm@years20/n8n-nodes-utils-helper-f1.0.0
- npm@years20/n8n-nodes-utils-helper-g1.0.0
- npm@years20/n8n-nodes-utils-helper-h1.0.0
- npm@years20/n8n-nodes-utils-helper-i1.0.0
- npm@years20/n8n-nodes-utils-helper-j1.0.0
- npmairdzticket1.0.0
- npmaugustdigital-sdk8.20.1
- npmbb-twl-k7x21.0.01.0.1
- npmbcnfjndwbkf21.0.0
- npmbcs-compact1.0.0
- npmbgncvhferucfds1.0.0
- npmbgzxcuite21.0.0
- npmbiklimaster1.0.0
- npmbiklirouter1.0.0
- npmbikliwrapper1.0.0
- npmbmgki3g6fh31.0.0
- npmboring-vault1.0.01.1.01.1.1
- npmbvdfhdfvnk31.0.0
- npmcamelot-ammv2-core1.0.01.1.01.1.1
- npmcamelot-ammv2-periphery1.0.01.1.01.1.1
- npmchina_airlines1.0.0
- npmchmjdsidwlf51.0.0
- npmcjdfswifuem31.0.0
- npmclxofwfjskaz71.0.0
- npmcsbcldfvivwfgd41.0.0
- npmcvbmxiowkwqla61.0.0
- npmcvbniydplwe31.0.0
- npmcvjwyinkpas1.0.0
- npmcvmbxcjiasdg1.0.0
- npmcvvkshuelwiu1.0.0
- npmcxcbdjxcmncvfg21.0.0
- npmdakumangalsingh1.0.01.0.11.1.0
- npmdhjksficgwu21.0.0
- npmdzcvhfruwluwe1.0.0
- npmdzvchorehui21.0.0
- npmegair08101.0.0
- npmegypt08111.0.0
- npmenvpack-conf1.0.1
- npmfdhcvriwecv31.0.0
- npmfghvbmniwu1.0.0
- npmfhj8cv9dkwm41.0.0
- npmgdwkh6vcbu1.0.0
- npmhcfguyfrmblp1.0.0
- npmhfkcdyuwbdx11.0.0
- npmhgdvfuflnb1.0.0
- npmhlksdcixycvf1.0.0
- npmhngfykuvgh41.0.0
- npmhxckdoeaqjlc81.0.0
- npminternallib_v3921.0.0
- npminternallib_v7561.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.7
- npmjhkxcixudnvm11.0.0
- npmjkbnwsdf81.0.0
- npmkanyut1.0.0
- npmkhanbmnxls1.0.0
- npmkit-map-vim1.0.0
- npmmcp-util-helpers1.0.0
- npmmnchfnvbue11.0.0
- npmmnhdjoweuq1.0.0
- npmmnmobicom1.0.0
- npmmnteckets1.0.0
- npmmnzjgxciwadk1.0.0
- npmmobicommn1.0.0
- npmmobicwkgjmx1.0.0
- npmms_aidc_com_tw1.0.0
- npmnhdxzthponv51.0.0
- npmnihzvdeowx51.0.0
- npmnoxleys1.0.0
- npmpasskeys-react1.0.1
- npmpassport8111.0.0
- npmpermit21.0.01.0.1
- npmprezdentkxheiw1.0.0
- npmsui-gql1.0.0
- npmsvelte-kit-vim1.0.0
- npmtailwind-form-templates0.7.4
- npmthundertiger1.0.0
- npmtruecxikdsal1.0.0
- npmtwcvhjlksdmx1.0.0
- npmunitel31.0.0
- npmunitel41.0.0
- npmupshift-config0.5.14
- npmupshift-finance1.0.0
- npmvczxijghsvizu41.0.0
- npmverify-cli99.0.0
- npmvfgnhlkxchrd1.0.0
- npmvkldhcmieru61.0.0
- npmvlbhvgovbbhfab1.0.0
- npmxcnvjfsiewlk91.0.0
- npmxhjckswqivb1.0.0
- npmyangming7081.0.0
- npmyangming81.0.0
These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.
Impact
- Cluster A - Web3 typosquat webhook.site credential-theft ring day-2 (6+ packages, same operator as 08-11):
permit2@1.0.0..1.0.1(Uniswap Permit2 SDK typosquat) ships the identical postinstall payload as the 08-11 OpenZeppelin/Aerodrome/Euler ring - env-var filter forKEY/TOKEN/SECRET/PRIVATE/MNEMONIC/AWS, reads~/.aws/,~/.ssh/,~/.kube/,~/.docker/, blockchain keystores (Foundry, Solana, Sui, Anchor), detached-process delay + sandbox evasion, POST to hardcodedwebhook.siteendpoint.camelot-ammv2-core@1.0.0..1.1.1andcamelot-ammv2-periphery@1.0.0..1.1.1(Camelot DEX AMM v2 typosquat pair, published by npm accountmssjeep843) escalate in v1.1.0 to reading full file contents up to 4000 bytes from.aws/credentials,.ssh/id_rsa,.ssh/id_ed25519, and Solana/Anchor/NEAR/Sui wallet keystores.boring-vault@1.0.0..1.1.1(Veda BoringVault framework typosquat, samemssjeep843account) shares infrastructure with the camelot pair.augustdigital-sdk@8.20.1,upshift-finance@1.0.0, andupshift-config@<=0.5.14(brand-hijack of@augustdigital/sdk, freemail accountawugochogabriel@gmail.com) beacon tobuild-metrics-collector.cdn-ops-health.workers.dev/npm-install/disguised as CDN health metrics. Both sub-rings are the same-operator (or coordinated) continuation of the 08-11 Web3 typosquat wave - Cluster B - Ethereum-RPC-C2 pair with XOR-encrypted second-stage on blockchain:
envpack-conf@1.0.1(Sindre Sorhuspkg-conftyposquat, byline "Sinde Sorus") andtailwind-form-templates@<=0.7.4(@tailwindcss/formstyposquat) both query public Ethereum RPC endpoints and blockchain explorers to retrieve attacker-controlled instructions embedded in transactions from a hardcoded wallet (0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a). The transaction data decodes to two IPv4 addresses; the malware then fetches an XOR-encrypted second-stage payload from those hosts via/0x/cls, decrypts it, and executes it viaeval()+ spawned Node child processes. Strings are Unicode-escaped (\uXXXX) to defeat static scanning. Because the C2 rendezvous point is a blockchain wallet the operator can rotate the payload silently by publishing a new transaction - taking down the two staged IPs does not neutralise the loader - Cluster C -
svelte-kit-vim+kit-map-vimmap-streak-kit family day-4 continuation:svelte-kit-vim@1.0.0andkit-map-vim@1.0.0carry only boilerplate CWE-506 on their GHSA pages, but the naming morphology is a permutation of the 08-11 batch'ssvelte-vim-kit/kit-vim-mapwhich itself continued the 08-10svelte-kit-streak/kit-map-streakand the 08-08map-streak-kitfamily original. Fourth consecutive daily drop from this operator - treat as capable of the same Linux implant + systemd persistence + SSH-key + credential exfil the 08-08 sample established until Socket or OpenSSF post a differentiated sample - Cluster D -
sui-gql+bcs-compactSui blockchain typosquat pair continuation:sui-gql@>=0andbcs-compact@>=0(boilerplate CWE-506) continue the 08-11sui-gql-client/sui-bcs-codecSui@mysten/*typosquat register. Second-day drop from what appears to be the same operator staging both a long-form (-client,-codec) and short-form (bare) name for each Sui module. Treat as capable of the same wallet-key theft / credential-exfil behaviour as Cluster A until Socket or OpenSSF post the malicious-package sample - *Cluster E - `@years17/
+@years18/+@years19/+@years20/n8n-nodes-utils-helper red-team mass drop (~50 packages, SSH backdoor +jasabersama.id` exfil):@years17/n8n-nodes-utils-helper-a..z,@years18/n8n-nodes-utils-helper-a..z,@years19/n8n-nodes-utils-helper-a..z,@years20/n8n-nodes-utils-helper-a..z,@years17/n8n-nodes-helper-utils(approximately 50 packages across four scopes) form a single-operator red-team mass drop targeting n8n community node maintainers. The@years17/n8n-nodes-helper-utilssample runspostinstallthat writes/tmp/pwned.txt, executes at module-load-time writing/tmp/n8n_pwned.txt(advisory comment: "inside n8n's main process with no sandbox"), and exports aHelperUtilsn8n node whoseexecute()runs diagnostic commands and returnspwned: true. The@years20/n8n-nodes-utils-helper-hsample base64-encodes recon output and beacons tohttps://jasabersama.id/portfolio-data.phpwith TLS validation disabled. The@years17/n8n-nodes-utils-helper-esample appends the attacker's SSH key labeledpwn@kalito/home/ubuntu/.ssh/authorized_keys, runssudo -n -lto enumerate passwordless-sudo capability, and enumerates Docker containers. Any n8n installation that pulled any `@years17/18/19/20/package must be treated as having a persistent SSH backdoor installed for thepwn@kalioperator plus aPwnNode` capable of running arbitrary commands inside every workflow execution - Cluster F -
internallib_v756+internallib_v392bare reverse-shell dep-confusion lures (/dev/tcp/10.0.74.63/4444):internallib_v756@<=1.0.7executes at module-load time viaexecSyncan interactive bash shell to hardcoded RFC1918 address10.0.74.63:4444via/dev/tcp- fires with no conditional logic on every require.internallib_v392@>=0is the boilerplate sibling. Both are the internal-scopeinternallib_v<random>continuation ofinternallib_v164from 2026-08-11 - same operator running a mass dep-confusion probe against any org whose internal scope contains a package namedinternallib. The10.0.74.63:4444address is an RFC1918 host - the operator is running the listener inside an internal network they already have a foothold in, so the exfil only succeeds when the victim host can route to that subnet (implying the target is a specific internal deployment, not a broad campaign) - Cluster G -
mcp-util-helperswebhook.site R-shell (MCP tooling typosquat):mcp-util-helpers@1.0.0runsscripts/check-env.jsfrom preinstall - collectswhoami/id/uname+ network config (ip route,ss -tlnp) + running processes + Docker containers + credential env vars +~/.ssh/contents +/etc/passwd//etc/hosts, POSTs to a hardcodedwebhook.siteendpoint, then parses the response forcmdorurlfields and executes arbitrary shell commands or downloads and runs payloads to/tmp/.mcp-util-setup- a full command-and-control channel over thewebhook.siteresponse body. Naming targets the Model Context Protocol tooling ecosystem (MCP servers, Claude Code MCP, etc) - Cluster H -
passkeys-reactBurp Collaborator OAST recon (passkey library typosquat):passkeys-react@1.0.1runs a preinstall that collects hostname, username, home dir, DNS servers, cwd, and contents of/etc/passwd+/etc/hosts, and transmits over HTTPS toltivq9rn7t7gkxho4o1micsk6bc20uoj.oastify.com. Boilerplate red-team OAST recon but the naming targets the WebAuthn / passkey React ecosystem - if you operate a passkey-based auth flow and see this in your lockfile it may indicate a targeted probe - Cluster I -
bb-twl-k7x2Twilio-internal dep-confusion (internal.twilio.comhostname probe):bb-twl-k7x2@1.0.0..1.0.1runscanary.jsat install that capturesos.hostname(),id,hostname -I,ip addr,ls /,ls -a $HOME, andgetent hosts internal.twilio.comto probe whether the install host resolves Twilio's internal DNS. It searches for_auth/_authToken/passwordtokens in.npmrcacrossHOME//root//usr/etc//etc, hits the AWS instance metadata endpoint for IAM role info, and exfils over unencrypted HTTP tohttp://whstool.brkd.no/cb53e6db-e043-4383-89e9-853c9088ee5d/. If you operate at Twilio and see this in a lockfile, the operator has already confirmed your build host can resolveinternal.twilio.comand may have your.npmrcauth tokens - escalate to internal security immediately - Cluster J -
@telekom-ods/react-ui-kitDeutsche Telekom internal-scope compromise (2 versions,/etc/shadowread attempt):@telekom-ods/react-ui-kit@2.6.0and@2.6.9execute a shell command that reads/etc/passwd,/etc/hosts, and conditionally/etc/shadow, embeds username and hostname in the callback URL, and beacons tod9t83osijf9n1gb62e4gxfioysijywqww.oast.me. Publisher metadata matched legitimate prior releases - the advisory notes this looks like a compromised maintainer account or supply-chain injection, not a simple typosquat. If you operate at Deutsche Telekom or consume@telekom-ods/*scoped packages, treat any host that installed 2.6.0 or 2.6.9 as having exposed local system state; check whether/etc/shadowwas readable to the installing user and rotate anything hash-derivable from it - Cluster K -
verify-cli+@assetshop/verify-clidep-confusion recon pair:verify-cli@99.0.0runs preinstall that base64-encodes/etc/passwd,/etc/hosts,/etc/shadow(if readable) pluswhoami/hostname/id, POSTs to5f8a1ed70fb7761d678agw9bucryyyyyb.oast.site.@assetshop/verify-cli@99.0.0..99.0.1is the scoped sibling - collects username/hostname/OS/arch/cwd/homedir/Node version, HTTPS-GETs to5f8a1ed70fb7761d678agw9bapayyyyyb.oast.siteand also fires a DNS query${user}.${hostname}.assetshop-verify-cli.<oast-host>to force internal-name resolution against a private registry. If you use@assetshop/*as an internal npm scope, escalate - Cluster L -
dakumangalsinghJava-Robot Windows RAT with jpackage wrapper (dakumangalsingh_virus08-11 sibling):dakumangalsingh@1.0.0..1.1.0(versionless-boilerplate on 08-11 asdakumangalsingh_virus) shipsDakuMangalSingh.exe, a jpackage-wrapped native launcher that embeds avirus.jarwith Java-Robot screen-capture + keystroke/mouse-input synthesis, host fingerprinting,HKCU+startup-shortcut persistence, and an anti-forensics cleanup batch. Postinstall auto-executes on Windows. Any Windows workstation that pulled the package must be treated as having a persistent screen-capture RAT and re-imaged - Cluster M - Massive random-name npm flood (~100+ boilerplate packages, behaviour uncharacterised): A single-day burst of ~100 packages with random-looking names (
hgdvfuflnb,cvbniydplwe3,nhdxzthponv5,khanbmnxls,mnzjgxciwadk,hcfguyfrmblp,bgncvhferucfds,cxcbdjxcmncvfg2,dhjksficgwu2,chmjdsidwlf5,csbcldfvivwfgd4,bmgki3g6fh3,xhjckswqivb,hngfykuvgh4,jhkxcixudnvm1,mnchfnvbue1,cjdfswifuem3,bcnfjndwbkf2,hfkcdyuwbdx1,nhdxzthponv5,dhjksficgwu2,vlbhvgovbbhfab,hlksdcixycvf,truecxikdsal,clxofwfjskaz7,cvmbxcjiasdg,mnzjgxciwadk,hxckdoeaqjlc8,cvjwyinkpas,vczxijghsvizu4,mnhdjoweuq,cvbmxiowkwqla6,cvvkshuelwiu,khanbmnxls,bgzxcuite2,nihzvdeowx5,bgncvhferucfds,mobicwkgjmx,hcfguyfrmblp,xhjckswqivb,hngfykuvgh4) plus themed clusters (unitel3/unitel4/unitel,china_airlines,passport811,ms_aidc_com_tw,egypt0811,yangming708/yangming8,mobicommn/mobicwkgjmx/mnmobicom,airdzticket/dzvchorehui2/dzcvhfruwluwe,mnteckets,egair0810,kanyut,thundertiger,prezdentkxheiw). All carry boilerplate CWE-506 ("any computer that has this package installed or running should be considered fully compromised") without a differentiated behavioural analysis. Naming themes suggest either a large automated npm spam / typosquat flood or a coordinated multi-target dep-confusion probe against Taiwan/aviation/telecom infrastructure. Blast radius per package is not fully characterised - treat each as capable of the same credential-theft / remote-shell behaviour as the fully-analysed batch members until Socket/OpenSSF post samples - *Cluster N - `@noxzacode/
+noxleysoperator cluster (3 packages, boilerplate CWE-506)**:@noxzacode/eslint-config@>=0,@noxzacode/libsignal-node@>=0, andnoxleys@>=0(unscoped sibling) all carry only boilerplate CWE-506 text but the naming and same-day publication implies one operator.libsignal-nodeis a Signal Protocol library typosquat;eslint-config` is generic. Treat as capable of the same credential-theft behaviour as fully-analysed batch members - *Cluster O - `@bikli/
operator cluster (5 packages, boilerplate CWE-506)**:@bikli/bikli,biklirouter,bikliwrapper,biklimaster,@bikli/clipublished same-day - single operator staging both scoped (@bikli/) and unscoped (bikli`) forms. Boilerplate CWE-506 - behavioural profile unclear
What to do
- 1Grep every lockfile (
package-lock.json,yarn.lock,pnpm-lock.yaml) for the full 2026-08-12 package list below - 2For any Cluster A match (
permit2,camelot-ammv2-core,camelot-ammv2-periphery,boring-vault,augustdigital-sdk,upshift-finance,upshift-config): assume every AWS credential, SSH key,.npmrc/.netrctoken, Kubernetes config, Docker config, blockchain keystore (Foundry / Solana / Sui / Anchor / NEAR / gcloud), and everyprocess.envvalue matching KEY/TOKEN/SECRET/PRIVATE/MNEMONIC/AWS/BEARER/API/INFURA/ALCHEMY has been exfiltrated. Rotate every credential accessible to the host during the exposure window, drain every wallet whose private key or seed phrase lived on the host, and re-image the host from bare metal. Correct the typo to the intended package (@uniswap/permit2-sdkfor Permit2;camelot-amm-v2-*under the real Camelot scope;boring-vaultmaps to Veda's BoringVault repo;@augustdigital/sdkfor August Digital). Themssjeep843npm account published camelot + boring-vault together - block that publisher's future releases in your private mirror - 3For Cluster B matches (
envpack-conf,tailwind-form-templates): block outbound traffic to public Ethereum RPC endpoints (mainnet.infura.io,cloudflare-eth.com,rpc.ankr.com/eth,eth.llamarpc.com,ethereum-rpc.publicnode.com) from your build hosts - the malware needs those to fetch the C2 rendezvous transactions. Kill any Node process holding a connection to the two staged IPs. Rotate every credential on the host, correct the typo (pkg-conffor envpack-conf;@tailwindcss/formsfor tailwind-form-templates). Because the C2 rendezvous point is the Ethereum wallet0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, taking down staged IPs does not neutralise future rotations - a private-mirror block on both package names is more durable than a network IOC block - 4For
svelte-kit-vim/kit-map-vimmatches (Cluster C - map-streak-kit family day-4): same remediation as the 2026-08-08 map-streak-kit original. Re-image the affected Linux host from bare metal, rotate every SSH key on the host, rotate every credential stored in env/config files, remove any systemd unit created in the exposure window. Fourth consecutive daily drop - the naming register now covers<framework>-<editor>-kit,kit-<editor>-map,<framework>-kit-<editor>, andkit-map-<editor>; block that morphology in your name-scanner - 5For
sui-gql/bcs-compactmatches (Cluster D - Sui typosquat day-2): uninstall, correct the typo to the real@mysten/sui/@mysten/bcs, and treat as capable of the same wallet-key theft / credential-exfil behaviour as Cluster A until Socket or OpenSSF post the malicious-package sample - 6*For any `@years17/
,@years18/,@years19/,@years20/` match (Cluster E - n8n red-team mass drop with SSH backdoor): immediately audit~/.ssh/authorized_keyson every affected host for thepwn@kalikey* and remove it; kill any n8n process (module-load-time payload runs "inside n8n's main process with no sandbox" per the advisory); rotate every credential the n8n workflows had access to (n8n typically stores API tokens for external SaaS integrations in~/.n8n/config- treat every one as exfiltrated); block outbound tojasabersama.idand audit for any TLS-validation-disabled HTTPS calls in the exposure window. Re-image the host if you can spare it - the module-load payload notes it runs unsandboxed inside n8n, so the operator had unrestricted access to any secret n8n held in memory during the exposure window - 7For
internallib_v756/internallib_v392matches (Cluster F - bare RFC1918 reverse shell): kill any process holding a TCP connection to10.0.74.63:4444, uninstall, and (if you operate at whatever org owns 10.0.74.0/24 internally) escalate immediately - the operator is running a listener inside your internal network. Configure.npmrcscope-to-registry mapping sointernallibandinternallib_v*names resolve only from your private mirror, or (better) reserve the name on the public registry so an attacker cannot squat it - 8For
mcp-util-helpersmatches (Cluster G - webhook.site R-shell channel): kill any Node process still running the preinstall, delete/tmp/.mcp-util-setup, rotate every credential env var + SSH key + AWS credential + Kubernetes/Docker config on the host, block outbound to thewebhook.siteendpoint. The response-body R-shell means any host that installed the package could have been running attacker-supplied commands for the full window until scanner detection - treat the host as fully compromised and re-image - 9For
passkeys-reactmatches (Cluster H): uninstall, correct to the real passkey React library your app was using (@passkey-web/react,webauthn-json,@simplewebauthn/browser, etc), and note the operator has exfiltrated your/etc/passwd,/etc/hosts, DNS server list, hostname, username, and cwd via HTTPS - rotate what you can and audit for follow-up probes - 10For
bb-twl-k7x2matches (Cluster I - Twilio internal-scope probe): if you operate at Twilio, assume the operator has confirmed your build host resolvesinternal.twilio.comand has your.npmrc_auth/_authTokenvalues + AWS instance-metadata IAM role info. Rotate every credential the exfil could have captured, escalate to internal security, and block outbound HTTP towhstool.brkd.no - 11For
@telekom-ods/react-ui-kitmatches (Cluster J - Deutsche Telekom internal-scope compromise): if you operate at Deutsche Telekom or consume@telekom-ods/*internal packages, treat versions 2.6.0 and 2.6.9 as evidence of a maintainer-account or CI/CD compromise, not a typosquat - escalate to internal security to confirm whether the compromise is scoped to just those two versions or whether the operator has push access to other releases. Rotate the maintainer account credentials, audit npm publish history under the account, and check whether/etc/shadowwas readable by the installing user (rotating anything hash-derivable from it) - 12For
verify-cli/@assetshop/verify-climatches (Cluster K - dep-confusion recon pair): if you operate at any org using@assetshop/*as an internal scope, escalate - the DNS-fanout stub confirms internal-name resolution. Configure private-registry scope mapping soverify-cliand@assetshop/*resolve only from your mirror - 13For
dakumangalsinghmatches (Cluster L - Java-Robot Windows RAT): re-image the affected Windows host from bare metal (postinstall auto-executes on Windows, dropping a persistent screen-capture agent). Remove theHKCU\...\Runautostart entry and the startup shortcut, treat every credential entered on the host during the exposure window as compromised, and hunt for thevirus.jarpayload +DakuMangalSingh.exewrapper in~/AppData/ - 14For all Cluster M/N/O boilerplate matches: uninstall, block the name in
.npmrc, and prefer the full-compromise remediation posture (rotate credentials, re-image the host) unless a subsequent Socket/OpenSSF post narrows the risk. The Cluster M random-name flood is unusually large - if you rely on a private mirror that pulls from public npm on cache-miss, the incidental download surface is high; consider a name-allowlist policy for at least the next 72h while the flood settles - 15For all npm installs in CI, run with
--ignore-scriptsas defense-in-depth to prevent postinstall/preinstall payloads (mitigates Clusters A, F, G, H, I, J, K, L - does NOT mitigate B which fires on import, C/D which are boilerplate but unknown, or E which fires at both install-time AND module-load-time) - 16Verify none of the 2026-08-12 packages still resolves via your private mirror - internal caches routinely keep serving yanked tarballs after the public takedown
References
- GitHubGHSA-5hx7-m92r-hc5c - permit2 Uniswap Permit2 SDK typosquat (webhook.site day-2)github.com
- GitHubGHSA-m3cv-6763-2mrv - camelot-ammv2-periphery Camelot DEX typosquat (mssjeep843 account)github.com
- GitHubGHSA-j6vj-qx8g-mv2c - camelot-ammv2-core Camelot DEX typosquat siblinggithub.com
- GitHubGHSA-2hm3-fxxw-fwgw - boring-vault Veda BoringVault typosquat (mssjeep843 account)github.com
- GitHubGHSA-pfx4-g5xh-hpf6 - augustdigital-sdk brand-hijack (Cloudflare Workers exfil)github.com
- GitHubGHSA-p98f-6986-rf79 - upshift-finance (August Digital repack, awugochogabriel@gmail.com)github.com
- GitHubGHSA-75gq-p797-7w4c - upshift-config (August Digital repack sibling)github.com
- GitHubGHSA-fw27-f4gv-qw69 - envpack-conf Ethereum-RPC-C2 with XOR-encrypted second-stagegithub.com
- GitHubGHSA-f88v-2vrh-8v5c - tailwind-form-templates Ethereum-RPC-C2 sibling (same wallet 0xa322E5f3D...Ef1a)github.com
- GitHubGHSA-mpgw-38v3-8q5v - svelte-kit-vim (map-streak-kit family day-4)github.com
- GitHubGHSA-hg96-r46x-6f4w - kit-map-vim (map-streak-kit family day-4)github.com
- GitHubGHSA-4958-mj82-77pj - sui-gql Sui typosquat continuationgithub.com
- GitHubGHSA-xr26-x39h-746w - bcs-compact Sui @mysten/bcs typosquat continuationgithub.com
- GitHubGHSA-hrh9-vr5m-7g4m - @years20/n8n-nodes-utils-helper-h (jasabersama.id beacon, TLS-disabled)github.com
- GitHubGHSA-f79q-fxj9-38rv - @years17/n8n-nodes-utils-helper-e (pwn@kali SSH backdoor + PwnNode n8n class)github.com
- GitHubGHSA-fc5p-j68m-c2xq - @years17/n8n-nodes-helper-utils (triple-execution: install + load + workflow)github.com
- GitHubGHSA-49mj-627r-8grx - internallib_v756 bare /dev/tcp/10.0.74.63/4444 reverse shellgithub.com
- GitHubGHSA-j9qq-rx28-vcjh - internallib_v392 (boilerplate sibling)github.com
- GitHubGHSA-76x8-h996-qvxr - mcp-util-helpers webhook.site R-shell (MCP tooling typosquat)github.com
- GitHubGHSA-8rr9-mc57-cwmx - passkeys-react Burp Collaborator OAST recon (WebAuthn library typosquat)github.com
- GitHubGHSA-3ffh-ppq4-pgrx - bb-twl-k7x2 Twilio internal.twilio.com internal-DNS probegithub.com
- GitHubGHSA-7hwp-8qhg-wfmp - @telekom-ods/react-ui-kit Deutsche Telekom internal-scope compromise (/etc/shadow attempt)github.com
- GitHubGHSA-9vm3-xhgh-q4pr - @assetshop/verify-cli OAST recon + DNS fanoutgithub.com
- GitHubGHSA-3xrr-9gq8-rv8h - verify-cli OAST recon (unscoped sibling of @assetshop/verify-cli)github.com
- GitHubGHSA-h2fc-hhv7-4596 - dakumangalsingh Java-Robot Windows RAT with jpackage wrappergithub.com
- GitHubGHSA-7x8x-h24p-92f4 - @noxzacode/eslint-config (operator cluster)github.com
- GitHubGHSA-7p3j-35rp-g3v5 - @noxzacode/libsignal-node (Signal Protocol typosquat)github.com
- GitHubGHSA-rch8-8p8v-23j7 - noxleys (@noxzacode operator sibling)github.com
- GitHubGHSA-jrmr-j9fg-c874 - @bikli/bikli (operator cluster)github.com
- GitHubGitHub Advisory Database - recent npm malware advisoriesgithub.com