GitHub Advisory malware sweep - 2026-08-20 batch (PyPI `libasync` cryptominer typosquat continuation of `2026-07-pyqt6darktheme` register, PyPI `rc4-secure` OpenSSF PoC, npm `express-route-engine` jsonbin.io eval-loader, `base99-85x` base-x typosquat with plaintext key exfil to `168.231.81.80`, `mc-provider` Cosmos-registry impersonator with `supersig` transitive dropper, `x6842179305` XOR-Function dropper, `ai-texts-utils`+`ai-texts` bundled obfuscator payload, dep-confusion PoC families `dolyame-*`+`fb-*`+`devplatform-*`+`digital-interview-*`+`pfp-*`+`bigops-*`, express+eslint+create-react-app typosquat cluster, blockchain-toolkit typosquats `ethereum-validator`+`polygon-toolkit-validate`)
31 GHSA CWE-506 advisories in the 24h ending 2026-08-20 06:00 UTC. Headliners: PyPI libasync cryptominer with Windows-registry persistence (campaign 2026-08-libasync, continuation of 2026-07-pyqt6darktheme), npm express-route-engine eval-loader that fetches JSON payloads from jsonbin.io, and base99-85x base-x typosquat that streams caller-supplied private-key/seed material in cleartext to 168.231.81.80.
Versions named here: 3.6.3