GitHub Advisory npm CWE-506 sweep - 2026-08-11 batch (webhook.site Web3 typosquat credential-theft ring `@openzeppelin-4/5/contracts`+`@aerodrome-finance/contracts`+`@aerodrome-finance/slipstream`+`ethereum-vault-connector`, `safe-local-env-loader` env-local RAT sibling, `newtun` unencrypted-WebSocket PTY RAT with self-update, `svelte-vim-kit`+`kit-vim-map` map-streak-kit family continuation, `@nzeros/codebreak` Go ELF disguised as C solver, `base65-*` base-x typosquat cluster with 123KB obfuscated payload + `bs58-*` boilerplate siblings, coordinated `oastify.com`/`sslip.io`/webhook OAST dep-confusion recon beacons)
38 npm CWE-506 advisories published 2026-08-11. Headline: five-package Web3 typosquat ring (@openzeppelin-4/contracts, @openzeppelin-5/contracts, @aerodrome-finance/contracts, @aerodrome-finance/slipstream, ethereum-vault-connector) sharing the same webhook.site credential-exfil TTP with 60-240s detached-process delay + sandbox evasion, safe-local-env-loader continuing the 2026-08-10 env-local Windows RAT, and newtun shipping a PTY reverse shell with self-update.
Versions named here: 1.0.0, 2.0.0, 3.0.0, 4.0.0, 4.0.1, 5.0.0, 5.0.1, 5.0.2