Malicious Code Digest 83

Xygeni Malicious Code Digest 83

Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 114 malicious packages between August 7 and August 14, 2026, led by an npm package cluster openly branded after a real dark-LLM attacker tool, a dependency-confusion wave targeting DeFi and Web3 protocol libraries, and a large-scale brand-squatting campaign against a Brazilian fintech provider.

The most attention-grabbing find: wormgpt-cli on npm, nine versions published in rapid succession on August 7, alongside a companion package, gpt-terminal-cli, published the same day. The name is a direct reference to WormGPT, a real dark-LLM tool marketed to cybercriminals for phishing and malware generation, suggesting the package is trading on the brand recognition of an actual attacker tool rather than hiding behind a neutral name.

A separate cluster targeted decentralized finance infrastructure directly: ten package names on npm impersonating real DeFi protocol and standards libraries (ethereum-vault-connector, boring-vault, camelot-ammv2-core, camelot-ammv2-periphery, @aerodrome-finance/contracts, @aerodrome-finance/slipstream, permit2, @openzeppelin-4/contracts, @openzeppelin-5/contracts, passkeys-react), sixteen confirmed versions in total, published within hours of each other on August 11. It’s a dependency-confusion play aimed squarely at developers building on Camelot, Aerodrome Finance, and OpenZeppelin’s standard contracts.

The largest single cluster this week impersonated Alelo, a Brazilian corporate benefits and payment card provider: ten distinct package names (alelo-core, alelo-api, alelo-client, alelo-utils, alelo-auth, alelo-sdk, alelo-services, alelo-common, alelo-payment, meualelo), most published in two or three versions, for twenty-one confirmed packages on August 14 alone. Alongside it, a separate scoped-namespace campaign published twenty-one lookalike n8n-nodes-utils-helper-* packages across three npm scopes (@years17, @years18, @years20) between August 13 and 14, a pattern consistent with automated squatting against the n8n automation platform’s node ecosystem rather than a single hand-crafted attack.

Two Maven packages published under io.github.davidtimur/c2-lab on August 7 are worth flagging on name alone. C2 is short for command-and-control, and a package advertising that function in its own name is either remarkably careless or testing how fast detection catches up. For more on Maven-specific supply chain risk, see our analysis of JavaCDoor, a compile-time backdoor we uncovered in the Maven ecosystem.

This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats and provide actionable intelligence to help DevSecOps teams protect their pipelines before damage occurs.

Ecosystem Package Date
mavenio.github.davidtimur/c2-lab:1.0.2August 07, 2026
mavenio.github.davidtimur/c2-lab:1.0.0August 07, 2026
npmopencode-browser-cdp:0.1.1August 07, 2026
npmopencode-browser-cdp:0.1.0August 07, 2026
npmopencode-browser-cdp:0.2.0August 07, 2026
npmloom-code:1.1.0August 07, 2026
npm@nxtedition/rocksdb:17.3.5August 07, 2026
npm@flame0510/rev4a:1.1.4August 07, 2026
npmpayscribe-links:0.1.2August 07, 2026
npmglobal-intel:1.0.1August 09, 2026
npmct-fivem:1.1.3August 09, 2026
npmct-fivem:1.1.4August 09, 2026
npmbjm-low-code-components:99.0.0August 09, 2026
npmsimple-date-formatter-new-9:1.0.0August 09, 2026
npmsimple-date-formatter-new-10:1.0.0August 09, 2026
pypikotoraka:0.1.0August 10, 2026
pypibtcflip:0.1.0August 10, 2026
pypibtcflx:0.1.0August 10, 2026
npmhex-encode-utils:1.0.0August 10, 2026
npmnolimit-agent:1.0.346August 13, 2026
npmethereum-vault-connector:1.0.0August 11, 2026
npmboring-vault:1.0.0August 11, 2026
npmcamelot-ammv2-periphery:1.0.0August 11, 2026
npmcamelot-ammv2-core:1.0.0August 11, 2026
npm@aerodrome-finance/slipstream:1.0.0August 11, 2026
npm@aerodrome-finance/contracts:1.0.0August 11, 2026
npmcamelot-ammv2-periphery:1.1.0August 11, 2026
npmboring-vault:1.1.0August 11, 2026
npmethereum-vault-connector:1.1.0August 11, 2026
npmcamelot-ammv2-core:1.1.0August 11, 2026
npm@aerodrome-finance/slipstream:1.1.0August 11, 2026
npm@aerodrome-finance/contracts:1.1.0August 11, 2026
npmpermit2:1.0.0August 11, 2026
npm@openzeppelin-5/contracts:1.0.0August 11, 2026
npm@openzeppelin-4/contracts:1.0.0August 11, 2026
npmpasskeys-react:1.0.1August 11, 2026
npmsui-bcs-codec:1.0.2August 11, 2026
npmexiouss:2.0.20August 12, 2026
pypienvprovision:1.2.0August 12, 2026
npm@ks-cqc/fingerprint-generator:1.99.99August 12, 2026
npm@years17/n8n-nodes-helper-utils:1.0.5August 13, 2026
npm@years17/n8n-nodes-utils-helper-d:1.0.0August 14, 2026
npm@years18/n8n-nodes-utils-helper-a:1.0.0August 14, 2026
npm@years18/n8n-nodes-utils-helper-b:1.0.0August 14, 2026
npm@years18/n8n-nodes-utils-helper-c:1.0.0August 14, 2026
npm@years18/n8n-nodes-utils-helper-d:1.0.0August 14, 2026
npm@years18/n8n-nodes-utils-helper-e:1.0.0August 14, 2026
npm@years18/n8n-nodes-utils-helper-f:1.0.0August 14, 2026
npm@years18/n8n-nodes-utils-helper-g:1.0.0August 13, 2026
npm@years18/n8n-nodes-utils-helper-l:1.0.0August 13, 2026
npm@years18/n8n-nodes-utils-helper-k:1.0.0August 13, 2026
npm@years18/n8n-nodes-utils-helper-j:1.0.0August 13, 2026
npm@years18/n8n-nodes-utils-helper-m:1.0.0August 13, 2026
npmxrblocks-mcp:6.3.1August 13, 2026
npmmagika-js:4.1.1August 13, 2026
npmgaarf:3.2.1August 13, 2026
npmupload-to-gcp:3.2.1August 13, 2026
npm@years20/n8n-nodes-utils-helper-d:1.0.0August 13, 2026
npm@years20/n8n-nodes-utils-helper-b:1.0.0August 13, 2026
npm@years20/n8n-nodes-utils-helper-e:1.0.0August 13, 2026
npm@years20/n8n-nodes-utils-helper-c:1.0.0August 13, 2026
npm@years20/n8n-nodes-utils-helper-a:1.0.0August 13, 2026
npm@years20/n8n-nodes-utils-helper-g:1.0.0August 13, 2026
npm@years20/n8n-nodes-utils-helper-h:1.0.0August 13, 2026
npm@years20/n8n-nodes-utils-helper-j:1.0.0August 13, 2026
pypiyoutube3-1:0.1.0August 13, 2026
npmgithub-policy-bot:1.0.0August 13, 2026
npmgaarf-node-bq:1.0.0August 13, 2026
npmgemini-cli-a2a-server:1.0.0August 13, 2026
npmwct-st:1.0.0August 13, 2026
npmtfjs-inference:1.0.0August 13, 2026
npmbazelisk:1.0.0August 13, 2026
npmcode-assist-mcp:1.0.0August 13, 2026
npmchromeos-webdriver-cli:1.0.0August 13, 2026
npmchromecast-webdriver-cli:1.0.0August 13, 2026
npmchrome-enterprise-premium-mcp:1.0.0August 13, 2026
npmgaarf-bq:1.0.0August 13, 2026
npmbroadcast-graphics-mcp:1.0.0August 13, 2026
npmxbox-one-webdriver-cli:1.0.0August 13, 2026
npmtizen-webdriver-cli:1.0.0August 13, 2026
npmtfjs-custom-module:1.0.0August 13, 2026
npmngsw-config:1.0.0August 13, 2026
npmlocalize-translate:1.0.0August 13, 2026
npmkarma-proxy:1.0.0August 13, 2026
npmlocalize-extract:1.0.0August 13, 2026
npmgaarf-node:1.0.0August 13, 2026
npminternallib_v756:1.0.7August 12, 2026
npmeyiouss:3.0.22August 13, 2026
npmeyiouss:3.0.21August 13, 2026
npmdate-fmt-helper-xz:1.0.4August 14, 2026
npmdatetime-format-xutil:1.0.0August 14, 2026
npmdatetime-fmt-xutil:1.0.0August 14, 2026
npmnotafollower1:1.0.8August 14, 2026
npmalelo-core:99.0.0August 14, 2026
npmalelo-core:99.0.1August 14, 2026
npmalelo-api:99.0.0August 14, 2026
npmalelo-client:99.0.0August 14, 2026
npmalelo-utils:99.0.0August 14, 2026
npmmeualelo:99.0.0August 14, 2026
npmalelo-auth:99.0.0August 14, 2026
npmalelo-sdk:99.0.0August 14, 2026
npmalelo-services:99.0.0August 14, 2026
npmalelo-common:99.0.0August 14, 2026
npmalelo-payment:99.0.0August 14, 2026
npmalelo-auth:99.0.2August 14, 2026
npmalelo-services:99.0.2August 14, 2026
npmalelo-payment:99.0.2August 14, 2026
npmalelo-common:99.0.2August 14, 2026
npmalelo-utils:99.0.2August 14, 2026
npmmeualelo:99.0.2August 14, 2026
npmalelo-api:99.0.2August 14, 2026
npmalelo-core:99.0.2August 14, 2026
npmalelo-sdk:99.0.2August 14, 2026
npmalelo-client:99.0.2August 14, 2026

When a Name Gives It Away: 114 Malicious Packages This Week

This week’s digest shows attackers leaning on brand recognition rather than hiding from it. wormgpt-cli went from zero to nine versions on npm in a single day, brazenly named after a real dark-LLM tool sold to cybercriminals, alongside a companion package, gpt-terminal-cli, published the same day. Two Maven packages went further still, publishing openly under the name c2-lab, command-and-control spelled out in the package name itself.

Volume told its own story elsewhere. A ten-package cluster impersonating DeFi protocol libraries (ethereum-vault-connector, boring-vault, camelot-ammv2-core, and others) landed sixteen confirmed versions within hours of each other on August 11, a synchronized drop aimed at developers pulling in what look like standard contracts from Camelot, Aerodrome Finance, and OpenZeppelin. Days later, a ten-name cluster impersonating Alelo, a Brazilian corporate benefits provider, produced twenty-one confirmed packages in a single day, while a parallel campaign squatted twenty-one lookalike n8n-nodes-utils-helper-* names across three separate npm scopes, a pattern that points to automated squatting infrastructure rather than one attacker working by hand.

Xygeni Early Malware Warning monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When a scoped namespace produces twenty-one lookalike packages in two days, or a Maven artifact ships with its intent in the name, detection that runs after the fact is already too late.

Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization needed to stay ahead of coordinated supply chain pressure, so your pipelines stay clean without slowing your teams down.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
Get your Free Account.
No credit card required.

Secure your Software Development and Delivery

with Xygeni Product Suite