malicious code digest 84

ملخص التعليمات البرمجية الضارة Xygeni 84

Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 34 malicious packages between August 15 and August 20, 2026, led by a sustained impersonation campaign against Baileys, a popular open-source WhatsApp Web API library, a cluster of Twilio/HackerOne-branded probe packages, and a set of unrelated-looking npm packages sharing an identical, unusually high version number.

The Baileys impersonation ran the longest: four separate package names (@mrlegendbot/baileys, cloud-baileys, @vanzxy/baileys, ourin-baileys) confirmed across six days, with cloud-baileys alone republished four times between August 15 and 20 under climbing version numbers, a pattern consistent with an attacker iterating past detection rather than a one-off upload.

A separate cluster on August 15 published packages referencing Twilio and HackerOne (twilio-hackerone-poc-afe6937c, five versions in one day, plus tw-pkgprobe-7731 و hunterone-build-probe-9210), naming conventions typically associated with bug-bounty or dependency-confusion probing rather than a disguised payload.

جدير بالذكر أيضاً: pump-segments-sdk, carbon-monorepoو pump-fun-skills, three otherwise unrelated package names all published at version 20.1.1 on August 19, an unusual shared version number across supposedly independent projects that suggests a single actor behind all three.

هذه اللقطة الأسبوعية هي جزء من عملنا المستمر ملخص التعليمات البرمجية الضارة, where we validate new threats to help DevSecOps teams protect their pipelineقبل حدوث الضرر.

النظام الإيكولوجي فئة الإشتراك التاريخ
الآلية الوقائية الوطنيةhunterone-build-probe-9210:1.0.015 أغسطس 2026
الآلية الوقائية الوطنيةtwilio-hackerone-poc-afe6937c:1.0.015 أغسطس 2026
الآلية الوقائية الوطنيةtw-pkgprobe-7731:1.0.015 أغسطس 2026
الآلية الوقائية الوطنيةtwilio-hackerone-poc-afe6937c:1.0.115 أغسطس 2026
الآلية الوقائية الوطنيةtwilio-hackerone-poc-afe6937c:1.0.215 أغسطس 2026
الآلية الوقائية الوطنيةtwilio-hackerone-poc-afe6937c:1.0.315 أغسطس 2026
الآلية الوقائية الوطنيةtwilio-hackerone-poc-afe6937c:1.0.415 أغسطس 2026
الآلية الوقائية الوطنية@mrlegendbot/baileys:1.2.415 أغسطس 2026
الآلية الوقائية الوطنيةcloud-baileys:1.1.315 أغسطس 2026
الآلية الوقائية الوطنية@vanzxy/baileys:1.4.216 أغسطس 2026
الآلية الوقائية الوطنيةourin-baileys:9.0.1116 أغسطس 2026
الآلية الوقائية الوطنيةeyiouss:4.0.116 أغسطس 2026
الآلية الوقائية الوطنيةcloud-baileys:1.1.3316 أغسطس 2026
الآلية الوقائية الوطنيةmoidev:1.0.016 أغسطس 2026
الآلية الوقائية الوطنية@wangjiezhong/dsh-memory:0.1.117 أغسطس 2026
الآلية الوقائية الوطنية@wangjiezhong/dsh-memory:0.1.217 أغسطس 2026
الآلية الوقائية الوطنية@wangjiezhong/dsh-memory:0.1.317 أغسطس 2026
الآلية الوقائية الوطنية@wangjiezhong/dsh-memory:0.1.417 أغسطس 2026
الآلية الوقائية الوطنيةmoidevx:1.0.017 أغسطس 2026
الآلية الوقائية الوطنيةdxr-dos:0.1.217 أغسطس 2026
الآلية الوقائية الوطنيةdxr-dos:0.1.117 أغسطس 2026
الآلية الوقائية الوطنيةdxr-dos:0.1.317 أغسطس 2026
الآلية الوقائية الوطنيةcloud-baileys:1.1.3418 أغسطس 2026
بايبيreqcrypt:0.1.018 أغسطس 2026
الآلية الوقائية الوطنيةdxrs-dos:0.1.318 أغسطس 2026
الآلية الوقائية الوطنيةprism-registry:1.0.118 أغسطس 2026
الآلية الوقائية الوطنيةoptimizely-starter-kit-for-fastly-compute:1.0.118 أغسطس 2026
الآلية الوقائية الوطنية@mohamed_nowisar/canary-confirm-token3:0.0.118 أغسطس 2026
الآلية الوقائية الوطنية@mohamed_nowisar/depconf-canary-test:0.0.118 أغسطس 2026
الآلية الوقائية الوطنية@mohamed_nowisar/token3-check:0.0.118 أغسطس 2026
الآلية الوقائية الوطنيةpump-segments-sdk:20.1.119 أغسطس 2026
الآلية الوقائية الوطنيةcarbon-monorepo:20.1.119 أغسطس 2026
الآلية الوقائية الوطنيةpump-fun-skills:20.1.119 أغسطس 2026
الآلية الوقائية الوطنيةcloud-baileys:1.1.3520 أغسطس 2026

When Iteration Beats Detection: 34 Malicious Packages This Week

This week’s digest shows attackers leaning on persistence rather than a single lucky upload. The cloud-baileys impersonation of the popular WhatsApp Web API library was republished four separate times between August 15 and 20 under climbing version numbers, joined by three other lookalike names (@mrlegendbot/baileys, @vanzxy/baileys, ourin-baileys), a sustained campaign rather than a one-off attempt.

Naming conventions gave other clusters away just as fast. A group of packages branded around Twilio and HackerOne, including twilio-hackerone-poc-afe6937c published in five versions in a single day, alongside tw-pkgprobe-7731 و hunterone-build-probe-9210, used naming patterns typically associated with bug-bounty or dependency-confusion probing. Elsewhere, three unrelated package names (pump-segments-sdk, carbon-monorepo, pump-fun-skills) all shipped under the identical version number 20.1.1 on the same day, an unusual coincidence that points to one actor operating behind all three.

تحذير مبكر من البرامج الضارة من Xygeni monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When the same package name resurfaces four times in six days under a new version each time, detection that only checks once is already behind.

زيجيني Open Source Security توفر المنصة لفرق DevSecOps إمكانية الكشف والتحديد الفوري للأولويات اللازمة للبقاء في طليعة ضغوط سلسلة التوريد المنسقة، وبالتالي pipelineحافظ على نظافة فريقك دون إبطاء أدائه.

أدوات تحليل التركيبات البرمجية sca
إعطاء الأولوية للمخاطر التي تتعرض لها برامجك، ومعالجتها، وتأمينها
احصل على حسابك المجاني.
أي بطاقة ائتمان.

قم بتأمين تطوير البرامج الخاصة بك وتسليمها

مع مجموعة منتجات Xygeni