GitHub Advisory malware sweep - 2026-09-04/05 batch (`houdus` Windows sandbox-detection dropper + `timeweave` Windows WinExec dropper + Box internal dep-confusion via `canarytokens.com` DNS + `tailwind-contact-forms` crypto-drainer typosquat + `line-through` + `real-router-telemetry` + `claude-channel-discord` recon + amirgo4496 PyPI dep-confusion campaign)
Multi-ecosystem sweep. houdus (PyPI, Sept 5) is a Windows-only sandbox-detecting dropper; timeweave fetches Windows executables from globaltimedata.com via WinExec. Also: Box internal dep-confusion via canarytokens.com DNS, tailwind-contact-forms crypto-drainer typosquat, line-through/real-router-telemetry webhook.site exfil, and the amirgo4496 PyPI dep-confusion campaign.
Versions named here: 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7, 0.5.8, 0.5.9, 0.5.10, 0.5.11, 0.5.12