ሰኔ ተንኮል አዘል ኮድ ማጠቃለያ

የተንኮል አዘል ኮድ አጭር መግለጫ ወርሃዊ ማጠቃለያ፡ ሐምሌ

Welcome to the July edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed over 780 malicious packages across npm, PyPI, and OpenVSX (the VS Code extension marketplace), tracked across five weekly digests.

July was defined by three converging trends: sustained, high-volume version-flooding campaigns designed to outlast takedowns; a sharp escalation in attacks targeting AI tooling, MCP servers, and agentic workflows; and coordinated dependency-confusion campaigns against both enterprise namespaces and crypto/DeFi ecosystems.

በዚህ ወር ከተመዘገቡት በጣም ታዋቂ ዘመቻዎች መካከል፡-

  • bingo-ai on PyPI resurfaced twice, flooding the registry with well over 150 versions across two bursts (July 13 and July 21), confirming this is an ongoing operation, not a one-off.
  • zevairouter became July’s largest single-package campaign: over 65 versions across npm, published continuously from July 25–28.
  • gcli-control, the Windows RAT we profiled in detail that routes its C2 through npoint.io, escalated from version 0.1.0 to 0.13.0 across three separate weeks.
  • @szc-ft/mcp-szcd-client, the package behind SkillLeak, our writeup on a credential decryptor delivered through a bundled MCP skill, was confirmed July 2.
  • The week of July 7 brought the month’s heaviest AI-tooling targeting: mcp-server-pg, anthropic-toolkit, openai-agents-helpers, ollama-helpers, እና @langgraphjs/toolkit, impersonating MCP, Anthropic, OpenAI, Ollama, and LangGraph.
  • A 17-package PayPal impersonation cluster hit npm July 27, all at version 28.0.0 within minutes.
  • @wagni_bot, roughly 60 npm packages impersonating crypto wallet SDKs (Ethereum, Solana, Binance, and more), all published in a single day, July 10.
  • Over a dozen fake VS Code extensions surfaced on OpenVSX, confirming attackers are expanding beyond package registries into the IDE itself.

The defining pattern of July: attacks increasingly target the AI agents and automated tooling that install packages with no human reviewer in the loop, at a publishing velocity built to outrun manual review.

Below is a summary of what we found. You can see all five weeks’ data disclosed in full detail at the Malicious Code Digest index.

ሳምንት 5፡ ከ180 በላይ ፓኬጆች ተገኝተዋል

ምህዳር ጥቅል ተረጋግ .ል ፡፡
ጥዋት@cryptosrvc/shift-sdk-v4:1.0.77ሐምሌ 24, 2026
ኦፕንቪኤስክስcesium/gltf-vscode:0.0.1ሐምሌ 24, 2026
ፒፒgcli-control:0.13.0ሐምሌ 24, 2026
VScodeairtune:1.0.0ሐምሌ 25, 2026
ጥዋትzevairouter:1.0.109ሐምሌ 25, 2026
ጥዋትidentityauthorizationserv:28.0.0ሐምሌ 27, 2026
ጥዋትmerchantprefsservice-paypal:28.0.0ሐምሌ 27, 2026
ጥዋትxo-member-components:28.0.0ሐምሌ 27, 2026
ኦፕንቪኤስክስtechnosophos/vscode-helm:0.0.1ሐምሌ 27, 2026
ኦፕንቪኤስክስbastienboutonnet/vscode-dbt:0.0.1ሐምሌ 27, 2026
ጥዋትmarkscan:1.0.0ሐምሌ 28, 2026
ጥዋትiphouse:1.0.0ሐምሌ 28, 2026
ጥዋትakrai-report-new:1.0.0ሐምሌ 28, 2026
ፒፒvtranalytic:8.0.0ሐምሌ 28, 2026
ጥዋትgreatcall-customers-commandapi:99.0.0ሐምሌ 29, 2026
ጥዋትblots:2.1.1ሐምሌ 29, 2026
ጥዋት@ey-china/ey-assistant:1.0.1ሐምሌ 30, 2026
ጥዋትflydev:0.0.1ሐምሌ 30, 2026
ጥዋት@qtestorgz/sdk:1.0.0ሐምሌ 30, 2026

ሳምንት 4፡ ከ165 በላይ ፓኬጆች ተገኝተዋል

ምህዳር ጥቅል ተረጋግ .ል ፡፡
ጥዋትjavas-crypto:2.0.4ሐምሌ 17, 2026
ጥዋትክሎቨር-ኮድላብ-ሬሞተር-ፔይ-ክላውድ:99.9.9ሐምሌ 17, 2026
ጥዋትድህረ-ፋይናንስ፡99.0.0ሐምሌ 19, 2026
ጥዋትትዊሊዮ-ሰርቨርአልባ፡99.99.99ሐምሌ 21, 2026
ጥዋትየአቅርቦት ማዕከል፡ 1.0.1ሐምሌ 21, 2026
ጥዋት@offa/offa-uwk:999.0.0ሐምሌ 21, 2026
ጥዋትdate-format-utils-xz:1.0.1ሐምሌ 21, 2026
ፒፒቢንጎ-አይ:6.2.241ሐምሌ 21, 2026
ጥዋት@bpa-internal/bpa-utils:99.99.99ሐምሌ 22, 2026
ጥዋትn8n-ኖዶች-pwn:1.0.1ሐምሌ 22, 2026
ፒፒgcli-control:0.1.0ሐምሌ 22, 2026
ጥዋትuniswap-sdk-v4:1.0.0ሐምሌ 23, 2026
ጥዋትwagmi-react:1.0.0ሐምሌ 23, 2026
ጥዋትኤተር-ሴኩሪቲ፡1.0.0ሐምሌ 23, 2026
ፒፒgcli-control:0.12.0ሐምሌ 24, 2026
ጥዋትdatefmt-pro:1.0.1ሐምሌ 24, 2026
ጥዋት@daylightqc/date-fmt-lite:1.0.0ሐምሌ 24, 2026

ሳምንት 3፡ ከ145 በላይ ፓኬጆች ተገኝተዋል

ምህዳር ጥቅል ተረጋግ .ል ፡፡
ጥዋትenv-fast:1.0.0ሐምሌ 11, 2026
ፒፒጨረቃ-ዩቪ:0.0.25ሐምሌ 12, 2026
ጥዋትgoogle-caja-bower:1000.800.20ሐምሌ 13, 2026
ጥዋትየብልት-ጥቅል:99.9.14ሐምሌ 13, 2026
ፒፒቢንጎ-አይ:6.2.109ሐምሌ 13, 2026
ጥዋትbugexploit:99.9.9ሐምሌ 13, 2026
ጥዋትamdocs-core-package:11.11.11ሐምሌ 14, 2026
ጥዋትarb-kit:1.0.0ሐምሌ 14, 2026
ጥዋትsolana-key-utils:1.0.0ሐምሌ 14, 2026
ጥዋትaxios-test-one:1.18.9ሐምሌ 15, 2026
ፒፒplungerhacker:2.0.1ሐምሌ 15, 2026
ፒፒlog-guru:0.7.8ሐምሌ 16, 2026
ፒፒፒሎጎራ፡ 0.7.8ሐምሌ 16, 2026
ጥዋት@across-toolkit/eslint-config:99.0.0ሐምሌ 17, 2026
ጥዋትvalidpilot-mcp:1.4.0ሐምሌ 17, 2026
ጥዋትnyxora:26.7.17ሐምሌ 17, 2026

ሳምንት 2፡ ከ200 በላይ ፓኬጆች ተገኝተዋል

ምህዳር ጥቅል ተረጋግ .ል ፡፡
ፒፒፕሮዋየር፡ 5.2.7ሐምሌ 4, 2026
ጥዋትኒዮን-ተርሚናል፡0.3.0ሐምሌ 4, 2026
ጥዋትnolimit-agent:1.0.336ሐምሌ 6, 2026
VScodeአንድሮይድ-ድጋፍ-ፍሬምወርክ-ከ:0.0.1 ጋርሐምሌ 6, 2026
ጥዋትmcp-server-pg:1.0.0ሐምሌ 7, 2026
ጥዋትአንትሮፒክ-toolkit:1.3.1ሐምሌ 7, 2026
ጥዋትኦፔንታይ-ኤጀንቶች-ረዳቶች፡ 1.3.3ሐምሌ 7, 2026
ጥዋትdebugcli:4.4.1ሐምሌ 7, 2026
ጥዋትhello244a:1.0.38ሐምሌ 7, 2026
ጥዋትተንደር-ሮኒ:99.9.9ሐምሌ 8, 2026
ፒፒጨረቃ-ዩቪ:0.0.5ሐምሌ 9, 2026
ጥዋትes6-codify:2.0.0ሐምሌ 9, 2026
ጥዋትn8n-nodes-mcputils:0.1.4ሐምሌ 9, 2026
ጥዋት@wagni_bot/hyperliquid-sdk:1.0.0ሐምሌ 10, 2026
ጥዋት@wagni_bot/metemask-sdk:1.0.0ሐምሌ 10, 2026
ጥዋት@wagni_bot/pumpfun-sdk:1.0.0ሐምሌ 10, 2026
ጥዋት@wagni_bot/binance-sdk:1.0.0ሐምሌ 10, 2026
ጥዋት@wagni_bot/ethereum-wallet:1.0.0ሐምሌ 10, 2026
ጥዋትየሙከራ-d3do:99.9.9ሐምሌ 10, 2026
ጥዋትየደንበኛ-ኩኪዎች-ወኪል:99.9.6ሐምሌ 10, 2026

ሳምንት 1፡ ከ90 በላይ ፓኬጆች ተገኝተዋል

ምህዳር ጥቅል ተረጋግ .ል ፡፡
ጥዋትየተረገሙ-ሞጁሎች:999.1.2ሐምሌ 1, 2026
ጥዋት@szc-ft/mcp-szcd-client:0.39.0ሐምሌ 2, 2026
ጥዋትpp-react-v5:30.0.2ሐምሌ 1, 2026
ጥዋትኮንስቴላ:0.5.1ሐምሌ 1, 2026
ጥዋትdate-fns-lite:1.0.9ሐምሌ 2, 2026
ጥዋት@easypayment/medusa-paypal:0.7.6ሐምሌ 2, 2026
ጥዋትdl-pp-latm:80.4.2ሐምሌ 2, 2026
ጥዋት@sudoughnym/enviro-demo:99.99.99ሐምሌ 1, 2026
ጥዋትnolimit-agent:1.0.316ሐምሌ 2, 2026
ጥዋትየተረገመች-ecto-d3ab00:1.0.0ሐምሌ 3, 2026
ጥዋት@checkrhq/adjudication-api-client:0.0.2ሐምሌ 3, 2026

From Version Storms to AI Impersonation: What July’s Supply Chain Attacks Reveal

The campaigns above aren’t edge cases, they’re the baseline now. Version-flooding storms, coordinated impersonation drops, and AI-tooling lookalikes are hitting real teams in real SDLCs every week, often with no human in the loop between publication and install.

የዚጄኒ የማልዌር ማወቂያ supply chain security platform gives organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. Coverage spans npm, PyPI, OpenVSX, and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.

እያንዳንዱ ግኝት በራስ-ሰር ቅድሚያ የሚሰጠው በብዝበዛ፣ ተደራሽነት እና በንግድ ተጽእኖ ነው፣ ስለዚህ ቡድንዎ በትክክል ማስተካከል በሚፈልገው ላይ እንጂ በጫጫታ ላይ አይደለም።

በ Xygeni Security Team የተረጋገጠውን እያንዳንዱን ተንኮል አዘል ፓኬጅ እና ዘመቻ ያስሱ የተንኮል አዘል ኮድ ዝርዝር.

ደህንነትዎን ይጠብቁ። ​​በፍጥነት ይቆዩ። በXygeni ቁጥጥር ስር ይሁኑ።

sca-tools-software-composition-analyse-tools
የሶፍትዌር አደጋዎችዎን ቅድሚያ ይስጡ፣ ያስተካክሉ እና ይጠብቁ
ነፃ መለያ ያግኙ።
ምንም ዱቤ ካርድ አያስፈልግም።

የሶፍትዌር ልማትዎን እና አቅርቦትዎን ደህንነት ይጠብቁ

ከ Xygeni Product Suite ጋር