GitHub Advisory malware sweep - 2026-09-17 late + 2026-09-18 (npm Baileys-fork `libsignal`-hijack wave `xzvbailey`/`xzvbailsx`/`zero-baileys`/`@lekzo/baileys` unpinned GitHub-ref RCE; `blue-string-formatter-utils` `xss.report/c/k3rne111` require-time eval loader; `@railone/image-utils` `api.npoint.io/641d37178a880b1e8b8f` sibling of `process-lhpm`/`process-mite`; `xa424234657567` `duel.com` host-gated `unpkg.com/x6842179305` remote payload; `tailwindcss-form-utils`/`-form-ui` Ethereum-on-chain C2 (`0xa322E5f3...` publicnode/drpc/1rpc); `@tink/tink-link-core@9.9.10` + `test89078-auth@99.99.99` dep-confusion DNS OOB pair; pip `requests-auroras`/`-triwes`/`-asetwe` `2.34.2` setup.py reverse shells + probes; pip `marketing-mcp` webhook.site SSH/AWS-key exfil MCP tool; pip `aiosendletter`/`index-forum`/`pyjstat-smooth` cloned-legit file exfil; npm `kartykgithub-multiversion-a` pentest continuation; 25x `lisa-*` tea.xyz autopublish flood)
GHSA 2026-09-17 late + 2026-09-18: 4x npm Baileys-fork packages redirect libsignal to unpinned GitHub refs for install-time RCE; blue-string-formatter-utils runs xss.report XMLHttpRequest+eval on require; @railone/image-utils reuses the api.npoint.io loader pattern of process-lhpm/process-mite; tailwindcss-form-* typosquats fetch commands from an attacker-authored Ethereum address; pip marketing-mcp exfils ~/.ssh/id_rsa + ~/.aws/credentials via a webhook.site endpoint.
Versions named here: 1.5.0, 2.5.0, 2.5.1, 2.5.2, 2.5.3, 2.5.4, 2.5.5, 2.5.6, 2.5.7, 2.5.8, 2.5.9, 2.5.10, 2.5.11, 2.5.12, 2.5.13, 2.5.14, 2.5.15, 2.5.16, 2.5.17