MALICIOUS CODE

Malicious Code Digest Monthly Recap: December

Welcome to the latest edition of the Xygeni Malicious Code Digest (Monthly Edition). Once again, our security teams have been diving deep into real package data to spot what traditional tools often miss. The goal? Catch and block malicious packages before they land in your codebase or pipeline.

Over the past few weeks, we’ve confirmed over 280 malicious packages spreading across npm and PyPI. Many used advanced tactics like typosquatting, dependency confusion, and data exfiltration, all designed to slip past automated checks and compromise your environment.

This monthly update is part of our ongoing malware report, where we publish weekly findings, confirm new threats, and help DevSecOps teams stay ahead. If you want full context across every malicious package we’ve analyzed, make sure to explore the complete malicous code digest here.

Important note:

this list does not include the packages affected by the second wave of the Shai Hulud npm supply chain attack. You can find the full breakdown of that campaign, along with all impacted packages, in our dedicated analysis:

⇒ Shai-Hulud 2.0 NPM Supply Chain Attack

Week 4: Over 16 Packages Discovered

Ecosystem Package Date
npmsecguest-lib:1.0.0Dec 19, 2025
npmppppparserfruit:0.30.1Dec 19, 2025
npmviktorparserctf5:1.0.0Dec 19, 2025
npmviktorparserctf7:1.0.0Dec 19, 2025
npmviktorparserctf8:1.0.0Dec 19, 2025
npm@aa-techops-ui/ping-authentication:1.0.6Dec 23, 2025
npm@aa-techops-ui/ping-authentication:3.99.99Dec 23, 2025
npm@aa-techops-ui/ping-authentication:2.99.99Dec 23, 2025
npm@aa-techops-ui/ping-authentication:4.99.99Dec 23, 2025
npm@aa-techops-ui/ping-authentication:5.99.99Dec 23, 2025
npmxbox-bottomnav:99.9.9Dec 19, 2025
npmsarumaan_a:1.1.2Dec 19, 2025
npm@ikarem/telemetry:100.1.0Dec 19, 2025
npm@ikarem/telemetry:100.1.1Dec 19, 2025
npmshaktihacker2026:99.9.0Dec 22, 2025
npmutif-updated:99.0.0Dec 23, 2025

Week 3: Over 33 Packages Discovered

Ecosystem Package Date
npmwfui-dsm-react-ui:99.99.1Dec 15, 2025
npmlet1xx:8.0.0Dec 16, 2025
npmlet1xz:8.0.1Dec 16, 2025
npmlet1x:8.0.1Dec 16, 2025
npmlet1x1:8.0.3Dec 16, 2025
npmlet1x6:8.0.0Dec 16, 2025
npmlet1x7:8.0.0Dec 16, 2025
npmprivate-internal-sdk:1.0.0Dec 16, 2025
npmprivate-internal-sdk:1.0.1Dec 16, 2025
npm@ikarem/telemetry:100.0.6Dec 16, 2025

Week 2: Over 92 Packages Discovered

Ecosystem Package Version Confirmation Date
npmppppparserfruit0.30.1Dec 12, 2025
npmcdd-plugin-for-datawarrior8.0.0Dec 12, 2025
npmserval-integrations-common-frontend7.0.0Dec 10, 2025
npm@onlytoodles/crypto-jsa1.0.0Dec 10, 2025
npmpaypal-scripts-server-utils9.0.0Dec 12, 2025
npmphx-core9.0.0Dec 12, 2025
npm@vampirchik147/xml1.0.0Dec 12, 2025
npmvue2-amis-custom-widget1231.0.10Dec 12, 2025
pypikzip0.1.0Dec 12, 2025
npmasdfgh30.30.6Dec 12, 2025

Week 1: Over 63 Packages Discovered

Ecosystem Package Date
npmccs-react-lib:7.7.8Nov 5, 2025
npmreact-tmedia:2.1.4Nov 6, 2025
npmreact-ui-animates:1.7.6Nov 3, 2025
npmreact-tchart:1.4.5Nov 3, 2025
npmfaustjs-org-sitemm2:1.0.0Nov 7, 2025
npmgeopost-web-component:16.8.0Nov 3, 2025
npmexpress-document-sdk:99.0.0Nov 3, 2025
npmint_affirm_controllers:99.0.0Nov 3, 2025
npmfrontend-buenaspracticas:100.9.9Nov 3, 2025
npmctflibxmljs2:0.30.1Nov 3, 2025

Secure Your Open Source Dependencies against Vulnerabilities and Malicious Code

Malware isn’t just a theoretical risk anymore, it’s already hiding in public packages. With Xygeni’s Early Malware Detection, you can reduce exposure by catching threats as soon as they’re published, before they reach your pipeline.

Our real-time scanning and prioritization engine continuously monitors public registries like npm and PyPI. Malicious packages are blocked, flagged, and ranked based on impact, so you know exactly what needs fixing, and when. Whether it’s typosquatting, dependency confusion, or credential stealers, we help your team stay ahead.

If you want full visibility into weekly and monthly findings, check the complete Malicious Code Digest.

Stay secure. Stay fast. Stay in control with Xygeni.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
7-day free trial
No credit card required

Secure your Software Development and Delivery

with Xygeni Product Suite