npm typosquat sweep - `pump-stream-logger`, `pump-laserstream-parser`, `pino-zod`, `rollup-plugin-polyfill-connect` yanked
On 2026-06-26 npm yanked four malicious typosquat packages within hours of each other - pump-stream-logger, pump-laserstream-parser, and pino-zod were taken down within a 10-second window at 05:10 UTC, and rollup-plugin-polyfill-connect followed at 12:16 UTC. All four are GHSA-classified as CWE-506 Embedded Malicious Code; the package names target the Helius Solana streaming SDK, the Pino logger family, the Zod validation library, and the rollup-plugin-polyfill-node Rollup plugin.
Versions named here: 1.0.121, 1.0.122