GitHub Advisory malware sweep - 20+ npm packages (chai-as-*, brock-*, rebrandly-*, dep-confusion + typosquat batch) taken down 2026-06-30
On 2026-06-30 GitHub's Advisory Database dropped a coordinated batch of ~25 CWE-506 Embedded Malicious Code advisories against unrelated npm packages published between 2026-05-27 and 2026-06-30. The batch mixes at least four distinct sub-clusters: chai-as-persisted / chai-as-assured (Chai typosquats), brock-loader / brock-react-alerts (with a 9999.0.0 dep-confusion tag), the rebrandly-domains-* pair (both 9999.0.0), and a wider fan-out of standalone malicious names.
Versions named here: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 1.1.9