GitHub Advisory malware sweep - 2026-08-17 / 2026-08-18 batch (Sui blockchain `@mysten/*` typosquat days 4-5 continuation `sui-move-graphql`+`sui-move-rpc`+`sui-gql-core`+`bcs-core`+`bucket-protocol-sdk-v2`, Tinkoff BNPL dep-confusion tail `bnpl-blocks-independent-bnpl-search`, LEB128 encoding typosquat pair `leb128x`+`ulebkit`, generic CWE-506 boilerplate `blastradar`+`runtime-health`, PyPI Telegram-RAT trio `socks5901`+`infogram-bot`+`httpz-requests`)
13 GHSA CWE-506 advisories across npm + PyPI in the 24h ending 2026-08-18 06:00 UTC (extended 2026-08-19 with two late PyPI Telegram-RAT entries). Headline: five-package Sui blockchain typosquat continuation (sui-move-graphql, sui-move-rpc, sui-gql-core, bcs-core, bucket-protocol-sdk-v2) extends the @mysten/* typosquat register into day-4/5. Also: Tinkoff BNPL dep-confusion tail, leb128x+ulebkit LEB128 typosquat pair, generic CWE-506 pair, and a PyPI Telegram-RAT trio socks5901+infogram-bot+httpz-requests.
Versions named here: 1.0.0, 1.2.0, 1.2.1, 1.3.0, 1.4.0, 1.5.0, 1.6.0, 1.6.1, 1.7.0, 1.8.0, 1.9.0