GitHub Advisory malware sweep - 20 npm packages (Claude-Code / Vue-CLI "clavue" typosquat cluster, `na-rony` throwaway sextet, tailwind-core, common-tg-service six-month sleeper) taken down 2026-07-08 / 2026-07-09
On 2026-07-08 and 2026-07-09 GitHub's Advisory Database retired ~20 CWE-506 Embedded Malicious Code npm advisories, continuing the July take-down cadence at ~20 packages/day. Two distinct clusters: a clavue / Claude-Code typosquat family (myclaude-code, clavue, clavuepro, calvuepro, clavue-agent-sdk) targeting Anthropic AI CLI developers; and a *`na-rony throwaway sextet** - six packages published by one operator between 2026-07-08 03:22–03:39 UTC. Plus a tailwind-core typosquat carrying a real 4.3.x version history and the six-month sleeper common-tg-service` with 547 versions.
Versions named here: 8.8.57, 8.9.0, 8.9.1, 8.9.2, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.1.0, 9.1.1, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.3.0, 9.4.0, 9.4.1, 9.4.2, 9.4.3, 9.4.4, 9.4.5, 9.4.6, 9.4.7, 9.4.8, 9.4.9, 9.4.10, 9.4.11, 9.5.0, 9.5.1, 9.5.2, 9.6.0, 9.6.1, 9.7.0, 9.7.1, 9.7.2, 9.7.3, 9.8.0, 9.8.1, 9.9.0, 9.10.0, 9.10.1, 9.10.2, 9.10.3, 9.10.4, 9.11.0, 9.11.1, 9.11.2, 9.11.3, 9.11.4, 9.11.5, 9.11.6, 9.11.7, 9.12.0, 9.13.0, 9.14.0, 9.14.1, 9.15.0, 9.16.0, 9.22.0, 9.26.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, 10.1.0, 10.1.1, 10.1.2, 10.1.3, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.3.0, 10.3.1, 10.3.2, 10.4.0, 10.4.1, 10.4.2