Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 34 malicious packages between August 15 and August 20, 2026, led by a sustained impersonation campaign against Baileys, a popular open-source WhatsApp Web API library, a cluster of Twilio/HackerOne-branded probe packages, and a set of unrelated-looking npm packages sharing an identical, unusually high version number.
The Baileys impersonation ran the longest: four separate package names (@mrlegendbot/baileys, cloud-baileys, @vanzxy/baileys, ourin-baileys) confirmed across six days, with cloud-baileys alone republished four times between August 15 and 20 under climbing version numbers, a pattern consistent with an attacker iterating past detection rather than a one-off upload.
A separate cluster on August 15 published packages referencing Twilio and HackerOne (twilio-hackerone-poc-afe6937c, five versions in one day, plus tw-pkgprobe-7731 and hunterone-build-probe-9210), naming conventions typically associated with bug-bounty or dependency-confusion probing rather than a disguised payload.
Also worth flagging: pump-segments-sdk, carbon-monorepo, and pump-fun-skills, three otherwise unrelated package names all published at version 20.1.1 on August 19, an unusual shared version number across supposedly independent projects that suggests a single actor behind all three.
This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats to help DevSecOps teams protect their pipelines before damage occurs.
When Iteration Beats Detection: 34 Malicious Packages This Week
This week’s digest shows attackers leaning on persistence rather than a single lucky upload. The cloud-baileys impersonation of the popular WhatsApp Web API library was republished four separate times between August 15 and 20 under climbing version numbers, joined by three other lookalike names (@mrlegendbot/baileys, @vanzxy/baileys, ourin-baileys), a sustained campaign rather than a one-off attempt.
Naming conventions gave other clusters away just as fast. A group of packages branded around Twilio and HackerOne, including twilio-hackerone-poc-afe6937c published in five versions in a single day, alongside tw-pkgprobe-7731 and hunterone-build-probe-9210, used naming patterns typically associated with bug-bounty or dependency-confusion probing. Elsewhere, three unrelated package names (pump-segments-sdk, carbon-monorepo, pump-fun-skills) all shipped under the identical version number 20.1.1 on the same day, an unusual coincidence that points to one actor operating behind all three.
Xygeni Early Malware Warning monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When the same package name resurfaces four times in six days under a new version each time, detection that only checks once is already behind.
Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization needed to stay ahead of coordinated supply chain pressure, so your pipelines stay clean without slowing your teams down.





