As every week, our malware detection systems scan thousands of new and updated packages across public registries. We confirmed 13 malicious packages between September 7 and 11, 2026, with the Baileys impersonation campaign still running, the first Composer cluster we have flagged, and two more cases of the version-inflation pattern used in dependency confusion.
cloud-baileys shipped two more versions (1.1.39 and 1.1.40), extending a campaign that has now produced new identities for several weeks straight. Composer appeared for the first time with three PHP packages published under form-handling names (slimfit/slimbase, slimfit/formbase, gcform/formhelper), a reminder that these operations follow developers rather than ecosystems. @umschool/platform was published at 999.0.0, the inflated version number typical of dependency confusion, and twilio-hackerone-poc-b8f21a shipped two versions under a name that reads as a proof of concept against a specific vendor’s internal package namespace.
Also worth noting: darkglitch on PyPI shipped 1.4.4 and 1.4.5 within minutes of each other, and the registry itself confirmed syswatch and samaki after our earlier detection.
This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats to help DevSecOps teams protect their pipelines before damage occurs.
| Ecosystem | Package | Date |
|---|---|---|
| pypi | syswatch:1.0.0 | September 07, 2026 |
| pypi | samaki:0.4.9 | September 07, 2026 |
| composer | slimfit/slimbase:2.0 | September 07, 2026 |
| composer | slimfit/formbase:1.2 | September 07, 2026 |
| composer | gcform/formhelper:1.2 | September 07, 2026 |
| npm | cloud-baileys:1.1.39 | September 07, 2026 |
| npm | alloy-graphql:1.0.1 | September 08, 2026 |
| npm | @umschool/platform:999.0.0 | September 10, 2026 |
| npm | twilio-hackerone-poc-b8f21a:1.0.0 | September 10, 2026 |
| npm | twilio-hackerone-poc-b8f21a:1.0.1 | September 10, 2026 |
| npm | cloud-baileys:1.1.40 | September 11, 2026 |
| pypi | darkglitch:1.4.4 | September 11, 2026 |
| pypi | darkglitch:1.4.5 | September 11, 2026 |
Three Ecosystems, One Pattern: 13 Malicious Packages This Week
This week’s digest shows familiar operations widening their footprint: a campaign still publishing after weeks of detection, the first Composer cluster to appear here, and two packages using an inflated version number to win a resolution race.
cloud-baileys shipped 1.1.39 and 1.1.40 within days, consistent with an attacker who treats takedowns as a cost of operating rather than a reason to stop. Composer appeared for the first time with three PHP packages under form-handling names (slimfit/slimbase, slimfit/formbase, gcform/formhelper), a reminder that these operations follow developers, not ecosystems. And @umschool/platform was published at 999.0.0, the inflated version that exists for one reason: to outrank the internal package your teams actually wrote.
Xygeni Early Malware Warning monitors npm, PyPI, Maven, Composer, OpenVSX, and other registries in real time, flagging threats at publication, before they reach a build and before an AI agent installs them autonomously. When a campaign resurfaces week after week, detection that only checks once is already behind.
Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization to stay ahead of coordinated supply chain pressure.







