Welcome to the September edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed 104 malicious packages across npm and PyPI, tracked across four weekly digests.
September was defined by three converging trends: campaigns that carried straight over from August and kept going despite takedowns; dependency confusion at scale, with dozens of packages claiming inflated version numbers like 99.0.0 and 19999.x to hijack private namespaces; and a clear move toward the plugin and automation ecosystems developers trust with privileged access, such as Strapi, n8n and MCP.
Among the most notable campaigns documented this month:
- The self-deleting anti-proctoring operator returned on September 1, with
amicat,bmcat,eyevoxandmoidevhconfirmed alongside two new names from the same stem,moidevkandmoidevl. - Baileys, the WhatsApp Web API library impersonated throughout August, stayed under attack:
cloud-baileysreached versions1.1.37and1.1.38in the first week and1.1.41by September 19, making it one of the longest-running impersonations we have tracked. - A 21-package campaign (September 15 to 17) published fake Strapi plugins under the “meeb” tag, all at the identical version
3.6.8, alongside companion packages with names likeos-info-meeb322kandfs-pwn-meeb322k. - A single package,
@nimbusedge/auth, shipped 39 versions in one day (September 11), all numbered19999.xso they would outrank any legitimate internal version. - Dependency-confusion packages bearing corporate and internal-sounding names appeared every week:
etoro-cashout,etoro-analyticsandetoro-aggregator(September 11),concierge-sdkat99.99.99(September 13),@traktis/core(September 17), and@dbbhk/ui-components,@siriusbeyond/*and@alphaspace/coreat99.xin the last week of the month. - The “siriusbeyond” operator started with a single unscoped package on September 20 and came back four days later as a scoped family (
@siriusbeyond/auth,/ui,/utils), the same brand dressed as an internal package set. - Fake n8n workflow nodes recurred through the month, including
n8n-nodes-sysdiag2,n8n-nodes-buildcheckandn8n-nodes-data-transformer-utils, continuing a pattern first seen in August. - An MCP client,
mcp-consultasdeveiculos-client, was published in three versions on a single day (September 4), a reminder that the AI tooling layer is now part of the same supply chain. - Six numbered copies of
simple-date-formatter-new-*(11 to 16) were published on September 25, a scripted burst built to test which names get through.
The defining pattern of September: attackers are no longer only borrowing trusted names, they are borrowing trusted positions. Plugins, workflow nodes, MCP clients and private package namespaces all run with more access than a typical dependency, and they are exactly where September’s campaigns concentrated.
Below is a summary of what we found. You can see all four weeks’ data disclosed in full detail at the Malicious Code Digest index.
Week 5: 4 Packages Discovered
| Ecosystem | Package | Date |
|---|---|---|
| npm | @alphaspace/core:99.0.1 | September 26, 2026 |
| npm | @alphaspace/core:99.0.2 | September 26, 2026 |
| npm | @alphaspace/core:99.0.3 | September 26, 2026 |
| npm | cma-self-hosted-sandbox-cf:1.0.0 | September 26, 2026 |
Week 4: Over 24 Packages Discovered
| Ecosystem | Package | Confirmed |
|---|---|---|
| npm | test890-auth:1.0.0 | Sep 18, 2026 |
| npm | bulk-add-sdk:1.99.99 | Sep 19, 2026 |
| npm | cloud-baileys:1.1.41 | Sep 19, 2026 |
| npm | byted-commerce-materials:1.0.0 | Sep 20, 2026 |
| npm | my-auto-follow:1.0.7 | Sep 20, 2026 |
| npm | siriusbeyond:1.0.0 | Sep 20, 2026 |
| npm | sysverify:2.0.10 | Sep 22, 2026 |
| npm | n8n-nodes-data-transformer-utils:1.0.0 | Sep 23, 2026 |
| npm | take-home-caller-id:1.0.1 | Sep 23, 2026 |
| npm | @dbbhk/ui-components:99.0.0 | Sep 24, 2026 |
| npm | @siriusbeyond/auth:99.0.0 | Sep 24, 2026 |
| npm | @alphaspace/core:99.0.2 | Sep 25, 2026 |
| npm | simple-date-formatter-new-11:1.0.0 | Sep 25, 2026 |
Week 3: Over 81 Packages Discovered
| Ecosystem | Package | Confirmed |
|---|---|---|
| pypi | lucy-python-script-2030:0.1.1 | Sep 11, 2026 |
| npm | @nimbusedge/auth:19999.x (39 versions) | Sep 11, 2026 |
| npm | etoro-cashout:99.0.2 | Sep 11, 2026 |
| npm | etoro-analytics:99.0.2 | Sep 11, 2026 |
| pypi | aitextkit-py:0.1.1 | Sep 11, 2026 |
| npm | noblox-asset.js:7.4.0 | Sep 12, 2026 |
| npm | concierge-sdk:99.99.99 | Sep 13, 2026 |
| pypi | darkglitch:1.4.4 | Sep 15, 2026 |
| npm | fs-pwn-meeb322k:1.0.0 | Sep 15, 2026 |
| npm | strapi-plugin-os-info-meeb322k:3.6.8 | Sep 15, 2026 |
| npm | n8n-nodes-sysdiag2:2.0.2 | Sep 15, 2026 |
| npm | n8n-nodes-buildcheck:1.0.0 | Sep 15, 2026 |
| npm | csa-mfa:1.1.15 | Sep 16, 2026 |
| npm | strapi-plugin-tryccresh-meeb:3.6.8 | Sep 16, 2026 |
| npm | @traktis/core:99.99.2 | Sep 17, 2026 |
Week 2: 13 Packages Discovered
| Ecosystem | Package | Date |
|---|---|---|
| pypi | syswatch:1.0.0 | September 07, 2026 |
| pypi | samaki:0.4.9 | September 07, 2026 |
| composer | slimfit/slimbase:2.0 | September 07, 2026 |
| composer | slimfit/formbase:1.2 | September 07, 2026 |
| composer | gcform/formhelper:1.2 | September 07, 2026 |
| npm | cloud-baileys:1.1.39 | September 07, 2026 |
| npm | alloy-graphql:1.0.1 | September 08, 2026 |
| npm | @umschool/platform:999.0.0 | September 10, 2026 |
| npm | twilio-hackerone-poc-b8f21a:1.0.0 | September 10, 2026 |
| npm | twilio-hackerone-poc-b8f21a:1.0.1 | September 10, 2026 |
| npm | cloud-baileys:1.1.40 | September 11, 2026 |
| pypi | darkglitch:1.4.4 | September 11, 2026 |
| pypi | darkglitch:1.4.5 | September 11, 2026 |
Week 1: 18 Packages Discovered
| Ecosystem | Package | Confirmed |
|---|---|---|
| npm | amicat:1.0.0 | Sep 01, 2026 |
| npm | bmcat:2.0.9 | Sep 01, 2026 |
| npm | eyevox:1.0.0 | Sep 01, 2026 |
| npm | moidevh:1.0.0 | Sep 01, 2026 |
| npm | moidevk:1.0.0 | Sep 01, 2026 |
| npm | moidevl:1.0.0 | Sep 01, 2026 |
| pypi | syswatch:1.0.0 | Sep 02, 2026 |
| npm | cloud-baileys:1.1.37 | Sep 02, 2026 |
| npm | @stellarshift/token-units:1.0.3 | Sep 02, 2026 |
| npm | @stellarshift/evm-address-kit:1.0.3 | Sep 02, 2026 |
| npm | @stellarshift/abi-tools:1.0.3 | Sep 02, 2026 |
| npm | @stellarshift/chain-metadata:1.0.3 | Sep 02, 2026 |
| npm | @a23842/dsh-notifier:0.1.0 | Sep 03, 2026 |
| pypi | samaki:0.4.9 | Sep 04, 2026 |
| npm | cloud-baileys:1.1.38 | Sep 04, 2026 |
| npm | mcp-consultasdeveiculos-client:0.1.1 | Sep 04, 2026 |
| npm | mcp-consultasdeveiculos-client:0.1.0 | Sep 04, 2026 |
| npm | mcp-consultasdeveiculos-client:0.0.2 | Sep 04, 2026 |
From Baileys to Strapi: What September’s Supply Chain Attacks Reveal
The campaigns above show attackers moving up the trust chain. A library impersonation that has now survived two months of takedowns, dependency-confusion packages inflating their version numbers to outrank private namespaces, and fake Strapi plugins, n8n nodes and MCP clients built to run where developers grant the most access: all of it lands in real SDLCs every week, often installed by automated tooling before any human reads the package name.
Xygeni’s malware detection and CI/CD and supply chain security give organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. MEW, Xygeni’s malware engine, detects malicious packages before a signature exists, across npm, PyPI, OpenVSX and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.
Every finding is automatically prioritized by exploitability, reachability, and business impact, so your team focuses on what actually needs fixing, not noise.
Explore every malicious package and campaign validated by the Xygeni Security Team in the Malicious Code Digest.
Stay secure. Stay fast. Stay in control with Xygeni.







