As every week, our malware detection systems scan thousands of new and updated packages across public registries. This was a quiet week: we confirmed four malicious package versions in the last 120 hours, all on npm.
Three of them are @alphaspace/core, the version-inflation campaign from last week, now at 99.0.3. The fourth, cma-self-hosted-sandbox-cf, was confirmed by Xygeni on September 26. Its name reads like internal tooling, which is exactly why it’s worth checking in your lockfile.
This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats to help DevSecOps teams protect their pipelines before damage occurs.
| Ecosystem | Package | Date |
|---|---|---|
| npm | @alphaspace/core:99.0.1 | September 26, 2026 |
| npm | @alphaspace/core:99.0.2 | September 26, 2026 |
| npm | @alphaspace/core:99.0.3 | September 26, 2026 |
| npm | cma-self-hosted-sandbox-cf:1.0.0 | September 26, 2026 |
Back for a Third Round: 4 Malicious Package Versions This Week
A short week, but not an empty one: four confirmed versions, all on npm. @alphaspace/core returned at 99.0.3, the third inflated version of a name we flagged last week, and cma-self-hosted-sandbox-cf showed up dressed as internal tooling. One is a flagged name coming back, the other a new name that looks harmless. Both are reasons detection can’t wait for a signature.
Xygeni Malware Early Warning monitors npm, PyPI, Maven, Composer, OpenVSX and other registries in real time, flagging threats at publication, before they reach a build. Xygeni’s Open Source Security platform adds the prioritization DevSecOps teams need to act on them first.







