MALICIOUS CODE

Malicious Code Digest Monthly Recap: February

Welcome to the latest edition of the Xygeni Malicious Code Digest (Monthly Edition). Once again, our security team analyzed real package telemetry across public registries to identify what traditional scanners often overlook: malicious code designed to blend into trusted developer workflows.

Over the past few weeks, we confirmed more than 230 malicious packages, primarily across npm, with occasional PyPI cases. However, this month was not only about volume.

Our research team conducted two in-depth investigations into high-impact threats:

These were not simple typosquatting attempts. Both cases involved credential abuse techniques and supply chain manipulation designed to impact real CI/CD pipelines and production environments.

Beyond these investigations, recent waves continued to show automation-driven publishing, aggressive version inflation, and internal-tool impersonation patterns, alongside classic tactics such as typosquatting, dependency confusion, and data exfiltration. The objective remains consistent: bypass trust heuristics and quietly compromise developer systems before detection.

This monthly update is part of our ongoing malware report, where we publish validated findings, confirm emerging threats, and provide actionable intelligence to help DevSecOps teams stay ahead of supply chain risk.

For full context across every malicious package analyzed this month, explore the complete Malicious Code Digest.

Week 4: Over 30 Packages Discovered

Ecosystem Package Date
npmuxproject11:1.0.0Feb 23, 2026
npmopencraw:2026.2.15Feb 20, 2026
npmreact-dropzone-truffle:100.21.9Feb 23, 2026
npmdrikssy-sdk-test:1.0.8Feb 23, 2026
npm@powpegtest/powpeg:10.2.0Feb 23, 2026
npmeslint-validator:1.0.2Feb 23, 2026
npmselfbot-lofy:1.2.5Feb 23, 2026
npmng-vzbootstrap:1.0.1Feb 23, 2026
npmng-vzbootstrap:1.0.2Feb 23, 2026
npmvds-monarch:1.0.4Feb 23, 2026

Week 3: Over 20 Packages Discovered

Ecosystem Package Date
npmether-lint:5.9.0Feb 13, 2026
npmlibjs-cqs:90.9.0Feb 13, 2026
npmcollabs-merchants:99.9.12Feb 13, 2026
npmdespicable-me:3.0.0Feb 13, 2026
npmenvoy1:1.0.9Feb 13, 2026
npmecosystem_ui:11.0.0Feb 13, 2026
npmenvoy1:1.0.10Feb 13, 2026
npm@depro0x/despicable-me:6.0.0Feb 13, 2026
openvsxfelix2cn/anti-tools:1.10.141Feb 15, 2026
openvsxfelix2cn/anti-tools:1.10.142Feb 15, 2026

Week 2: Over 130 Packages Discovered

Ecosystem Package Date
npmmysqldbstool:1.0.4Feb 09, 2026
npm@acqui-calm-library/acqui-hero-carousel-section:999.99.999Feb 09, 2026
npmringcentral-google-drive-notification-add-in:2.2.2Feb 09, 2026
npmdate-fns-2:1.0.0Feb 09, 2026
npmredux-saga-task-cancel-rce:1.0.0Feb 09, 2026
npmteeseest:1.6.2Feb 09, 2026
npminternal-logger-embaby:9.9.10Feb 09, 2026
npm@xcxcxxx/gsap3:99.10.90Feb 09, 2026
npmbdf-server-clone:1.0.0Feb 09, 2026
npmreact-native-kraken-oauth:1.0.1Feb 09, 2026

Week 1: Over 50 Packages Discovered

Ecosystem Package Date
npmmonkey-tags:99.9.2Feb 05, 2026
npmmingw-trial:1.0.0Feb 05, 2026
npmsyf-api-legacy:1.0.0Feb 06, 2026
npmgoogle-audit-tool:1.0.0Jan 30, 2026
npmidv-script:1.0.1Feb 04, 2026
npmidv-script:1.0.3Feb 04, 2026
npmidv-script:1.0.4Feb 04, 2026
npm@anthropic-field/cli:0.3.1Feb 03, 2026
npm@anthropic-field/cli:0.3.0Feb 03, 2026
npm@anthropic-field/cli:0.2.1Feb 03, 2026

Secure Your Open Source Dependencies against Vulnerabilities and Malicious Code

Malware isn’t just a theoretical risk anymore, it’s already hiding in public packages. With Xygeni’s Early Malware Detection, you can reduce exposure by catching threats as soon as they’re published, before they reach your pipeline.

Our real-time scanning and prioritization engine continuously monitors public registries like npm and PyPI. Malicious packages are blocked, flagged, and ranked based on impact, so you know exactly what needs fixing, and when. Whether it’s typosquatting, dependency confusion, or credential stealers, we help your team stay ahead.

If you want full visibility into weekly and monthly findings, check the complete Malicious Code Digest.

Stay secure. Stay fast. Stay in control with Xygeni.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
7-day free trial
No credit card required

Secure your Software Development and Delivery

with Xygeni Product Suite