GitHub Advisory malware sweep - 18 npm packages (2 Claude / Anthropic-brand typosquats, 3-package `chain-sdk-js` / `theta-sdk-js` / `ai-pro-sdk` mid-July SDK cluster, 3-package `ai-p2p` / `websight-p2p` / `websight2-p2p` June 15 P2P burst, 3 auto-publisher sleepers `px8my` (55 versions) / `monogrok` (21 versions) / `scan-only` (16 versions), plus WordPress Gutenberg / terminal-toy / singleton fillers) retired 2026-07-16 → 2026-07-17
On 2026-07-16 and 2026-07-17 GitHub's Advisory Database retired 18 CWE-506 npm malware advisories (separate from 2 additional chai-as-* retirements folded into the existing jsonspack DPRK incident). Highlights: anthropic-claude-latest - a version-matched (4.7.1 / 4.7.2 / 4.7.3) typosquat of Anthropic's Claude Code CLI - and claude-token-tracker-mcp, an MCP-shape package targeting Claude Code's OAuth-token traffic (matching the Mitiga Labs "MCP token theft" attack chain that abuses .claude.json).
Versions named here: 1.0.1, 1.0.7, 1.0.8, 1.0.11, 1.0.14, 1.0.30, 1.0.31, 1.0.32, 1.0.33, 1.0.34, 1.0.35, 1.0.36, 1.0.37, 1.0.39, 1.0.40, 1.0.41, 1.0.43, 1.0.44