Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 35 malicious packages between August 28 and September 4, 2026, led by a fourteen-package cluster impersonating Brazilian payment infrastructure published in a single day, a continuation of the Baileys impersonation campaign under two new names, and a coordinated cluster of crypto/blockchain-themed packages sharing an identical version number.
The largest cluster of the week targeted what appears to be Brazilian fintech and credit-check infrastructure: fourteen packages (grafeno-products, spc-grafeno, grafeno-client, grafeno-utils, grafeno-core, grafeno-logger, grafeno-config, grafeno-auth, grafeno-pix, spc-grafeno-login, spc_login, grafeno-payments, grafeno-webhook, grafeno-billing) were all published on August 29, mostly at version 1.0.0, with grafeno-products standing out at an inflated 999.0.1, the same version-inflation pattern seen in last week’s e-commerce cluster.
The Baileys impersonation campaign flagged in prior weeks continued under two new identities: @fyxzpediaa/baileys:8.1.0 on August 28, and cloud-baileys, which shipped two versions (1.1.37 and 1.1.38) across the week.
Also worth flagging: a four-package cluster under the @stellarshift scope (token-units, evm-address-kit, abi-tools, chain-metadata), all published September 2 at the identical version 1.0.3, crypto and blockchain-tooling names consistent with targeting developers working in that space; and mcp-consultasdeveiculos-client, which shipped three versions in a single day (0.0.2, 0.1.0, 0.1.1 on September 4), an MCP client package, the kind of dependency an AI agent is increasingly likely to pull in on its own.
This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats to help DevSecOps teams protect their pipelines before damage occurs. This week we also posted Risky Business: Self-Deleting npm Packages Explained, worth a look if you want a deeper dive into how some of these campaigns cover their tracks after installation.
Fourteen Names, One Pattern: 35 Malicious Packages This Week
This week’s digest shows the same actor’s fingerprint scaled up: a single-day cluster of fourteen packages impersonating financial infrastructure, and two campaigns still iterating on aliases flagged in prior weeks.
The largest cluster this week gave itself away through both naming and version pattern. Fourteen packages built around Brazilian fintech and credit-check branding (grafeno-products, spc-grafeno, grafeno-client, grafeno-utils, grafeno-core, grafeno-logger, grafeno-config, grafeno-auth, grafeno-pix, spc-grafeno-login, spc_login, grafeno-payments, grafeno-webhook, grafeno-billing) all published on August 29, most at version 1.0.0 except grafeno-products, which shipped at an inflated 999.0.1, the same version-number tell that exposed last week’s e-commerce cluster.
The Baileys impersonation campaign flagged in prior digests hasn’t stopped, it’s rotated aliases. @fyxzpediaa/baileys appeared on August 28, and cloud-baileys shipped two more versions (1.1.37, 1.1.38) across the week, consistent with an attacker cycling through names rather than abandoning the attempt after detection.
A separate four-package cluster under the @stellarshift scope (token-units, evm-address-kit, abi-tools, chain-metadata) all published September 2 at the identical version 1.0.3, crypto and blockchain-tooling names aimed at developers working in that space. And mcp-consultasdeveiculos-client shipped three versions in a single day, an MCP client package, exactly the kind of dependency an autonomous agent is now positioned to pull in on its own without a human reading the name first.
Xygeni Early Malware Warning monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When fourteen unrelated-looking package names publish under the same day with the same inflated version pattern, or a campaign resurfaces under a third alias in as many weeks, detection that only checks once is already behind.
Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization needed to stay ahead of coordinated supply chain pressure, so your pipelines stay clean without slowing your teams down.







