dbmux maintainer-account takeover: four backdoored versions seeded across two release branches
Between 2026-06-04 and 2026-06-05 the dbmux npm maintainer account (bhagyamudgal) was hijacked and four backdoored releases were pushed across both the legacy 1.x and current 2.x branches: 1.0.5, 1.0.6, 2.2.4, 2.2.5. GHSA-62wx-5f55-w8g2 (published 2026-06-09) classifies all four as CWE-506 embedded malicious code: any host that installed or executed them should be treated as fully compromised. npm deprecated every malicious release; the clean latest is 2.2.3.
Versions named here: 1.0.5, 1.0.6, 2.2.4, 2.2.5