Welcome to the August edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed 407 malicious packages across npm, PyPI, and OpenVSX (the VS Code extension marketplace), tracked across four weekly digests.
August was defined by three converging trends: a sustained impersonation campaign targeting a single popular open-source library that outlasted multiple takedown attempts; coordinated “same version, same day” clusters across dozens of supposedly unrelated package names, the fingerprint of single operators running many fronts at once; and a shift toward mirroring real, trusted names, DeFi protocols, Google open-source tools, and enterprise internal packages, rather than generic junk names.
Among the most notable campaigns documented this month:
- Baileys, a popular open-source WhatsApp Web API library, was impersonated continuously across three separate weeks under four different aliases (
@mrlegendbot/baileys,cloud-baileys,@vanzxy/baileys,ourin-baileys), withcloud-baileysalone republished at least five times between mid- and late August. - QuietPolyfill’s original 20-package npm dropper campaign resurfaced under its own names,
beaver-ui-drawer,accounts-timeline,accounts-final-form,bcore-bravo-eslint-config, and others, confirmed August 1-3. - A 25-plus package wave hit OpenVSX in a single day (August 2), impersonating real developer extensions across ESLint, Rails, WordPress, and dozens of other tools.
- A 17-package DeFi cluster (August 11) impersonated Camelot, Aerodrome Finance, permit2, and OpenZeppelin’s contract libraries, all published in matching version pairs within hours.
- A striking cluster (August 13) typosquatted genuine Google open-source tools:
gaarf,magika-js,bazelisk, and a run of*-webdriver-clipackages, 20 packages riding on real tool names in a single day. - A 21-package cluster impersonated Alelo, a Brazilian payments company (August 14), the shape of a targeted dependency-confusion attempt against one organization’s internal namespace.
- A seven-package e-commerce-branded cluster (August 24) published under the identical version
99.0.1within the same day. - Authentication-themed packages recurred under five different naming conventions through the back half of the month:
totp-utils,secretkey-2fa,secretkey2fa,2fa-secretkey, andauth-otp.
The defining pattern of August: attackers increasingly mirror names that already carry trust, real protocols, real tools, real internal package conventions, rather than generic filler names, and they do it in tight, same-day bursts built to move faster than manual review.
Below is a summary of what we found. You can see all four weeks’ data disclosed in full detail at the Malicious Code Digest index.
Week 4: Over 53 Packages Discovered
| Ecosystem | Package | Confirmed |
|---|---|---|
| npm | @vanzxy/baileys:1.4.3 | Aug 22, 2026 |
| npm | totp-utils:1.4.5 | Aug 23, 2026 |
| npm | secret-key-totp:1.5.1 | Aug 23, 2026 |
| npm | sm-billing-form:99.0.1 | Aug 24, 2026 |
| npm | sm-payment:99.0.1 | Aug 24, 2026 |
| npm | auth-otp:1.0.3 | Aug 24, 2026 |
| npm | secretkey-2fa:1.0.1 | Aug 24, 2026 |
| pypi | minecraft-ytreceiver:0.1.0 | Aug 25, 2026 |
| npm | cloud-baileys:1.1.36 | Aug 26, 2026 |
| npm | zenntechinc-cli:1.6.6 | Aug 26, 2026 |
| npm | 2fa-secretkey:1.0.5 | Aug 28, 2026 |
Week 3: Over 34 Packages Discovered
| Ecosystem | Package | Confirmed |
|---|---|---|
| npm | twilio-hackerone-poc-afe6937c:1.0.0 | Aug 15, 2026 |
| npm | hunterone-build-probe-9210:1.0.0 | Aug 15, 2026 |
| npm | @mrlegendbot/baileys:1.2.4 | Aug 15, 2026 |
| npm | @vanzxy/baileys:1.4.2 | Aug 16, 2026 |
| npm | ourin-baileys:9.0.11 | Aug 16, 2026 |
| npm | cloud-baileys:1.1.34 | Aug 18, 2026 |
| npm | pump-segments-sdk:20.1.1 | Aug 19, 2026 |
| npm | carbon-monorepo:20.1.1 | Aug 19, 2026 |
| npm | pump-fun-skills:20.1.1 | Aug 19, 2026 |
| npm | cloud-baileys:1.1.35 | Aug 20, 2026 |
Week 2: Over 114 Packages Discovered
| Ecosystem | Package | Confirmed |
|---|---|---|
| npm | camelot-ammv2-core:1.0.0 | Aug 11, 2026 |
| npm | @aerodrome-finance/slipstream:1.0.0 | Aug 11, 2026 |
| npm | boring-vault:1.0.0 | Aug 11, 2026 |
| npm | permit2:1.0.0 | Aug 11, 2026 |
| npm | @openzeppelin-5/contracts:1.0.0 | Aug 11, 2026 |
| npm | gaarf:3.2.1 | Aug 13, 2026 |
| npm | magika-js:4.1.1 | Aug 13, 2026 |
| npm | bazelisk:1.0.0 | Aug 13, 2026 |
| npm | gemini-cli-a2a-server:1.0.0 | Aug 13, 2026 |
| npm | xbox-one-webdriver-cli:1.0.0 | Aug 13, 2026 |
| npm | @years17/n8n-nodes-helper-utils:1.0.5 | Aug 13, 2026 |
| npm | @years18/n8n-nodes-utils-helper-e:1.0.0 | Aug 14, 2026 |
| npm | @years20/n8n-nodes-utils-helper-h:1.0.0 | Aug 13, 2026 |
| npm | alelo-core:99.0.0 | Aug 14, 2026 |
| npm | alelo-auth:99.0.0 | Aug 14, 2026 |
| npm | alelo-sdk:99.0.0 | Aug 14, 2026 |
| npm | alelo-payment:99.0.0 | Aug 14, 2026 |
| npm | meualelo:99.0.0 | Aug 14, 2026 |
Week 1: Over 206 Packages Discovered
From Baileys to DeFi: What August’s Supply Chain Attacks Reveal
The campaigns above aren’t edge cases, they’re the baseline now. Sustained impersonation of a single trusted library, same-day version bursts across dozens of unrelated-looking names, and attackers mirroring real DeFi protocols, real Google tooling, and real enterprise namespaces instead of generic junk, all of it is hitting real teams in real SDLCs every week, often with no human in the loop between publication and install.
Xygeni’s malware detection and supply chain security platform gives organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. Coverage spans npm, PyPI, OpenVSX, and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.
Every finding is automatically prioritized by exploitability, reachability, and business impact, so your team focuses on what actually needs fixing, not noise.
Explore every malicious package and campaign validated by the Xygeni Security Team in the Malicious Code Digest.
Stay secure. Stay fast. Stay in control with Xygeni.







