GitHub Advisory malware sweep - 2026-09-22 (late) + 2026-09-23 (npm `@tvg-mar/*` + `@user-services/web-components` `oob.algamil7x.xyz` DNS-OOB day 6 at `9.9.10`; `hardhat-hold` axios-loader RCE typosquat wave extension; `chai-as-viem` + `chai-logger` chai/pino/jsonspack axios-loader family extension; `envforge/envparse` 6-package coordinated typosquat batch; `@wizloft/harness-*` 15-package Aug-Sep buildup batch quarantine; `oracle-redis` + `turbo-ws` transitive-dependency trojans; `@vitemirrorte/element-plus-vite-cli` `npmjs.it.com` mall4cloud-react-targeted RAT; `@gsutevil/hta-stage` Windows HTA/WSH MSI loader; org-internal dep-confusion cluster (`@tesla-insurance`, `devplatform-sdk`, `uolcs-host-uol-anuncios-fe`, `bnpl-blocks-*`, `bigops-*`, `agora402-payment-utils`, `ubiquiti-agents-link-mcp`, `internallib_v497/550` at RFC1918 `10.0.5.109`, `cisco-github-simple` oastify.com); pip `auclean` cloud-credential infostealer + `snap-queue`/`crypto-trader-py`/`poly-check-b` silent-install campaign + `kerokwis` pypi+rubygems telemetry; pentest `cloushaar-poc-exfil-91827` pip; ~60 random-name bulk quarantines)
GHSA 2026-09-22 (late) + 2026-09-23: ~120 new npm advisories + 5 pip + 2 rubygems. Day 6 of the oob.algamil7x.xyz DNS-OOB operator adds @tvg-mar/* and @user-services/web-components at 9.9.10. @vitemirrorte/element-plus-vite-cli@2.9.1 is a full Node RAT with npmjs.it.com C2 targeting mall4cloud-react. pip auclean steals cloud credentials.
Versions named here: 1.0.0