Malicious Code Digest August Recap

Malicious Code Digest Monthly Recap: August

Welcome to the August edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed 407 malicious packages across npm, PyPI, and OpenVSX (the VS Code extension marketplace), tracked across four weekly digests.

August was defined by three converging trends: a sustained impersonation campaign targeting a single popular open-source library that outlasted multiple takedown attempts; coordinated “same version, same day” clusters across dozens of supposedly unrelated package names, the fingerprint of single operators running many fronts at once; and a shift toward mirroring real, trusted names, DeFi protocols, Google open-source tools, and enterprise internal packages, rather than generic junk names.

Among the most notable campaigns documented this month:

  • Baileys, a popular open-source WhatsApp Web API library, was impersonated continuously across three separate weeks under four different aliases (@mrlegendbot/baileys, cloud-baileys, @vanzxy/baileys, ourin-baileys), with cloud-baileys alone republished at least five times between mid- and late August.
  • QuietPolyfill’s original 20-package npm dropper campaign resurfaced under its own names, beaver-ui-drawer, accounts-timeline, accounts-final-form, bcore-bravo-eslint-config, and others, confirmed August 1-3.
  • A 25-plus package wave hit OpenVSX in a single day (August 2), impersonating real developer extensions across ESLint, Rails, WordPress, and dozens of other tools.
  • A 17-package DeFi cluster (August 11) impersonated Camelot, Aerodrome Finance, permit2, and OpenZeppelin’s contract libraries, all published in matching version pairs within hours.
  • A striking cluster (August 13) typosquatted genuine Google open-source tools: gaarf, magika-js, bazelisk, and a run of *-webdriver-cli packages, 20 packages riding on real tool names in a single day.
  • A 21-package cluster impersonated Alelo, a Brazilian payments company (August 14), the shape of a targeted dependency-confusion attempt against one organization’s internal namespace.
  • A seven-package e-commerce-branded cluster (August 24) published under the identical version 99.0.1 within the same day.
  • Authentication-themed packages recurred under five different naming conventions through the back half of the month: totp-utils, secretkey-2fa, secretkey2fa, 2fa-secretkey, and auth-otp.

The defining pattern of August: attackers increasingly mirror names that already carry trust, real protocols, real tools, real internal package conventions, rather than generic filler names, and they do it in tight, same-day bursts built to move faster than manual review.

Below is a summary of what we found. You can see all four weeks’ data disclosed in full detail at the Malicious Code Digest index.

Week 4: Over 53 Packages Discovered

EcosystemPackageConfirmed
npm@vanzxy/baileys:1.4.3Aug 22, 2026
npmtotp-utils:1.4.5Aug 23, 2026
npmsecret-key-totp:1.5.1Aug 23, 2026
npmsm-billing-form:99.0.1Aug 24, 2026
npmsm-payment:99.0.1Aug 24, 2026
npmauth-otp:1.0.3Aug 24, 2026
npmsecretkey-2fa:1.0.1Aug 24, 2026
pypiminecraft-ytreceiver:0.1.0Aug 25, 2026
npmcloud-baileys:1.1.36Aug 26, 2026
npmzenntechinc-cli:1.6.6Aug 26, 2026
npm2fa-secretkey:1.0.5Aug 28, 2026

Week 3: Over 34 Packages Discovered

EcosystemPackageConfirmed
npmtwilio-hackerone-poc-afe6937c:1.0.0Aug 15, 2026
npmhunterone-build-probe-9210:1.0.0Aug 15, 2026
npm@mrlegendbot/baileys:1.2.4Aug 15, 2026
npm@vanzxy/baileys:1.4.2Aug 16, 2026
npmourin-baileys:9.0.11Aug 16, 2026
npmcloud-baileys:1.1.34Aug 18, 2026
npmpump-segments-sdk:20.1.1Aug 19, 2026
npmcarbon-monorepo:20.1.1Aug 19, 2026
npmpump-fun-skills:20.1.1Aug 19, 2026
npmcloud-baileys:1.1.35Aug 20, 2026

Week 2: Over 114 Packages Discovered

EcosystemPackageConfirmed
npmcamelot-ammv2-core:1.0.0Aug 11, 2026
npm@aerodrome-finance/slipstream:1.0.0Aug 11, 2026
npmboring-vault:1.0.0Aug 11, 2026
npmpermit2:1.0.0Aug 11, 2026
npm@openzeppelin-5/contracts:1.0.0Aug 11, 2026
npmgaarf:3.2.1Aug 13, 2026
npmmagika-js:4.1.1Aug 13, 2026
npmbazelisk:1.0.0Aug 13, 2026
npmgemini-cli-a2a-server:1.0.0Aug 13, 2026
npmxbox-one-webdriver-cli:1.0.0Aug 13, 2026
npm@years17/n8n-nodes-helper-utils:1.0.5Aug 13, 2026
npm@years18/n8n-nodes-utils-helper-e:1.0.0Aug 14, 2026
npm@years20/n8n-nodes-utils-helper-h:1.0.0Aug 13, 2026
npmalelo-core:99.0.0Aug 14, 2026
npmalelo-auth:99.0.0Aug 14, 2026
npmalelo-sdk:99.0.0Aug 14, 2026
npmalelo-payment:99.0.0Aug 14, 2026
npmmeualelo:99.0.0Aug 14, 2026

Week 1: Over 206 Packages Discovered

From Baileys to DeFi: What August’s Supply Chain Attacks Reveal

The campaigns above aren’t edge cases, they’re the baseline now. Sustained impersonation of a single trusted library, same-day version bursts across dozens of unrelated-looking names, and attackers mirroring real DeFi protocols, real Google tooling, and real enterprise namespaces instead of generic junk, all of it is hitting real teams in real SDLCs every week, often with no human in the loop between publication and install.

Xygeni’s malware detection and supply chain security platform gives organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. Coverage spans npm, PyPI, OpenVSX, and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.

Every finding is automatically prioritized by exploitability, reachability, and business impact, so your team focuses on what actually needs fixing, not noise.

Explore every malicious package and campaign validated by the Xygeni Security Team in the Malicious Code Digest.

Stay secure. Stay fast. Stay in control with Xygeni.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
Get your Free Account.
No credit card required.

Secure your Software Development and Delivery

with Xygeni Product Suite