MALICIOUS CODE january 26

Malicious Code Digest Monthly Recap: January 26

Welcome to the latest edition of the Xygeni Malicious Code Digest (Monthly Edition). Once again, our security teams have been diving deep into real package data to spot what traditional tools often miss. The goal? Catch and block malicious packages before they land in your codebase or pipeline.

Over the past few weeks, we’ve confirmed more than 180 malicious packages across npm (and occasional PyPI cases). Recent waves show heavy use of automation-driven publishing, version inflation, and internal-tool impersonation, alongside classic tactics like typosquatting, dependency confusion, and data exfiltration,  all designed to slip past automated checks and quietly compromise developer environments and CI/CD pipelines.

This monthly update is part of our ongoing malware report, where we publish weekly findings, confirm new threats, and help DevSecOps teams stay ahead. If you want full context across every malicious package we’ve analyzed, make sure to explore the complete malicous code digest here.

Week 4: Over 70 Packages Discovered

Ecosystem Package Date
npm@acqui-calm-library/acqui-hero-carousel-section:999.99.999Jan 23, 2026
npmcom.unity.xr.visionos:2.3.2Jan 27, 2026
npmvvvv4234:1.0.1Jan 27, 2026
npmfrontend-js-state-web:2.2.3Jan 27, 2026
npmgoogle-audit-tool:1.0.0Jan 30, 2026
npmsolhint-plugin-hyperlane:99.9.9Jan 27, 2026
npm@row-components/pricing-embedded-sui:77.7.7Jan 27, 2026
npmun112:1.0.39Jan 23, 2026
npmnot-remix:9.0.0Jan 28, 2026
npmtranslation-note:9.0.0Jan 27, 2026

Week 3: Over 44 Packages Discovered

Ecosystem Package Date
npmreact-server-dom-unbundled:9.2.31Jan 16, 2026
npmnatateste:1.1.0Jan 21, 2026
npmvictim-package-a:1.0.1Jan 21, 2026
npmworldnormal:1.0.0Jan 21, 2026
npmtypedoc-plugin-fuel-variants:1.0.1Jan 21, 2026
npmworldposition:1.0.0Jan 21, 2026
npmvworldviewdir:1.0.0Jan 21, 2026
npmforms-new-design:99.99.9Jan 21, 2026
npmdux-portal-privacy:4.9.121Jan 16, 2026
npmpresentation-test-utilities:0.0.1Jan 21, 2026

Week 2: Over 30 Packages Discovered

Ecosystem Package Date
npmjz-test-npm:114.8.10Jan 12, 2026
npminternallib_v147:1.0.1Jan 12, 2026
npmjz-test-npm:114.8.114Jan 12, 2026
npmforms-new-design:99.99.9Jan 12, 2026
npms3-cache-handler:0.1.0Jan 12, 2026
npm@icecreampie/internallib_v147:1.0.1Jan 12, 2026
npmpresentation-test-utilities:0.0.1Jan 12, 2026
npmnot-remix:9.0.0Jan 12, 2026
npmlyonscg:88.8.8Jan 12, 2026
npm@gwp-gtmt-components/event-listener:77.7.7Jan 12, 2026

Week 1: Over 40 Packages Discovered

Ecosystem Package Date
npmunescaped:1.0.0Jan 05, 2026
npmgithub-badge-bot:1.8.2Jan 02, 2026
pypisystem-health-check-test-unique:0.3.4Jan 02, 2026
pypipdatainstaller:1.0.0Jan 02, 2026
pypiqdatainstaller:1.0.1Jan 05, 2026
npm1231dai:1.0.0Jan 02, 2026
npmshopify-perf-kit:8.2.31Jan 02, 2026
npmshopify-perf-kit:8.2.32Jan 02, 2026
npmhello-world-npm-demo-example:1.0.0Jan 06, 2026
npmhello-world-npm-demo-example:1.0.1Jan 06, 2026

Secure Your Open Source Dependencies against Vulnerabilities and Malicious Code

Malware isn’t just a theoretical risk anymore, it’s already hiding in public packages. With Xygeni’s Early Malware Detection, you can reduce exposure by catching threats as soon as they’re published, before they reach your pipeline.

Our real-time scanning and prioritization engine continuously monitors public registries like npm and PyPI. Malicious packages are blocked, flagged, and ranked based on impact, so you know exactly what needs fixing, and when. Whether it’s typosquatting, dependency confusion, or credential stealers, we help your team stay ahead.

If you want full visibility into weekly and monthly findings, check the complete Malicious Code Digest.

Stay secure. Stay fast. Stay in control with Xygeni.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
7-day free trial
No credit card required

Secure your Software Development and Delivery

with Xygeni Product Suite