GitHub Advisory malware sweep - 18 npm packages (2 Claude / Anthropic-brand typosquats, 3-package `chain-sdk-js` / `theta-sdk-js` / `ai-pro-sdk` mid-July SDK cluster, 3-package `ai-p2p` / `websight-p2p` / `websight2-p2p` June 15 P2P burst, 3 auto-publisher sleepers `px8my` (55 versions) / `monogrok` (21 versions) / `scan-only` (16 versions), plus WordPress Gutenberg / terminal-toy / singleton fillers) retired 2026-07-16 → 2026-07-17
On 2026-07-16 and 2026-07-17 GitHub's Advisory Database retired 18 CWE-506 npm malware advisories (separate from 2 additional chai-as-* retirements folded into the existing jsonspack DPRK incident). Highlights: anthropic-claude-latest - a version-matched (4.7.1 / 4.7.2 / 4.7.3) typosquat of Anthropic's Claude Code CLI - and claude-token-tracker-mcp, an MCP-shape package targeting Claude Code's OAuth-token traffic (matching the Mitiga Labs "MCP token theft" attack chain that abuses .claude.json).
Versions named here: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11, 1.0.12, 1.0.13, 1.0.14, 1.0.15, 1.0.16, 1.0.17, 1.0.18, 1.0.19, 1.0.20, 1.0.21, 1.0.22, 1.0.23, 1.0.24, 1.0.25, 1.0.26, 1.0.27, 1.0.28, 1.0.29, 1.0.30, 1.0.31, 1.0.32, 1.0.33, 1.0.34, 1.0.35, 1.0.36, 1.0.37, 1.0.38, 1.0.39, 1.0.40, 1.0.41, 1.0.42, 1.0.43, 1.0.44, 1.0.45, 1.0.46, 1.0.47, 1.0.48, 1.0.49, 1.0.50, 1.0.51, 1.0.52, 1.0.53, 1.0.54