GitHub Advisory npm CWE-506 sweep - 33+ package 2026-08-07 batch (`remote-claude-daemon` full-desktop RAT via WebSocket relay + baileys-clone WhatsApp bot cluster + `@cats-cdf/*` OAST recon pair + `internallib_v514` internal LAN reverse-shell + `wormgpt-cli` LLM-branded RAT + `@united-airlines-org/atmos-design-system` dep-confusion + `@ks-video/kwai-player-web` telemetry beacon + `@avi892nash/aegis-grid-runner` Juspay-leaked internal RCE tool + `@junyoung-kim/reins` PTY-reverse-shell with systemd persistence + `noviembrenacional.com` WordPress-CSRF nuke pair + long tail)
GHSA published 33+ npm CWE-506 advisories dated 2026-08-07 spanning several clusters: remote-claude-daemon (Claude Code full-desktop RAT with screen + mic capture via WebSocket relay, 20 versions), a 4-package baileys-clone WhatsApp bot cluster (@prototypevip/baileys, diezyclutch-baileys, ynastore-baileys, and more), @cats-cdf/* OAST dep-confusion recon, internallib_v514 reverse-shell to hardcoded 10.0.70.90 (continuation of internallib_v<NNN> campaign), wormgpt-cli (LLM-branded RAT with clipboard theft), @united-airlines-org/atmos-design-system dep-confusion, @ks-video/kwai-player-web telemetry beacon, @avi892nash/aegis-grid-runner (leaked-internal-Juspay RCE tool), @junyoung-kim/reins (PTY reverse-shell with systemd persistence), and xxdxax+xdaxx (targeted WordPress CSRF/account-nuke against noviembrenacional.com).
Versions named here: 2.17.1, 3.1.1