MALICIOUS CODE november

Malicious Code Digest Monthly Recap: November

Welcome to the latest edition of the Xygeni Malicious Code Digest (Monthly Edition). Once again, our security teams have been diving deep into real package data to spot what traditional tools often miss. The goal? Catch and block malicious packages before they land in your codebase or pipeline.

Over the past few weeks, we’ve confirmed over 260 malicious packages spreading across npm and PyPI. Many used advanced tactics like typosquatting, dependency confusion, and data exfiltration, all designed to slip past automated checks and compromise your environment.

This monthly update is part of our ongoing malware report, where we publish weekly findings, confirm new threats, and help DevSecOps teams stay ahead. If you want full context across every malicious package we’ve analyzed, make sure to explore the complete malicous code digest here.

Important note:

this list does not include the packages affected by the second wave of the Shai Hulud npm supply chain attack. You can find the full breakdown of that campaign, along with all impacted packages, in our dedicated analysis:

⇒ Shai-Hulud 2.0 NPM Supply Chain Attack

Week 4: Over 83 Packages Discovered

Ecosystem Package Date
npm@rajank18/smart-commit:1.0.0Nov 24, 2025
npmeslint-plugin-whatever:9.0.1Nov 23, 2025
npmccs-react-lib:7.7.8Nov 23, 2025
npmhumhub:5.0.3Nov 23, 2025
npmhumhub:5.0.6Nov 23, 2025
npmacross-toolkit:9.0.1Nov 23, 2025
npmflaresdsdsdsdsd:45.0.0Nov 23, 2025
npm@secretcollect/identity-core:6.0.0Nov 23, 2025
npmstartupkit-umbraco-webpack:2.0.0Nov 23, 2025
npmtelstraprogrammablenetworkapilib:2.9.1Nov 23, 2025

Week 3: Over 49 Packages Discovered

Ecosystem Package Date
npmstudy-lab-npm-test:1.0.0Nov 07, 2025
npmstudy-lab-e53:1.0.0Nov 07, 2025
npm@acitons/artifact:4.0.13Nov 12, 2025
npmsupermoy1:0.30.1Nov 11, 2025
npmsupervot5:0.30.1Nov 11, 2025
npmfinalmoyloyt:0.30.1Nov 11, 2025
npmxmljs2bank:0.30.2Nov 11, 2025
npmbeijingcrisis:3.0.1Nov 11, 2025
npmsuperbankbackdoor:1.0.0Nov 11, 2025
npmsuperbankbackdoor:0.30.1Nov 11, 2025

Week 2: Over 62 Packages Discovered

Ecosystem Package Date
npmstack-ui-elements:1.0.0Oct 6, 2025
npmkn-nf-iso-properties-kn1:99.87.31Oct 6, 2025
npmeslint-plugin-paysafe:6.2.6Oct 7, 2025
npmwinston-logger-pro:1.1.1Oct 7, 2025
npmmerchantauxiliaryserv:1.0.0Oct 7, 2025
npmwinston-logger-pro:1.1.0Oct 7, 2025
npmgestion-usuarios:2.0.0Oct 7, 2025
npmincommincentives:2.2.0Oct 7, 2025
npmincommincentives:2.2.1Oct 7, 2025
npmoxrvxaslllcaj:1.0.0Oct 7, 2025

Week 1: Over 63 Packages Discovered

Ecosystem Package Date
npmccs-react-lib:7.7.8Nov 5, 2025
npmreact-tmedia:2.1.4Nov 6, 2025
npmreact-ui-animates:1.7.6Nov 3, 2025
npmreact-tchart:1.4.5Nov 3, 2025
npmfaustjs-org-sitemm2:1.0.0Nov 7, 2025
npmgeopost-web-component:16.8.0Nov 3, 2025
npmexpress-document-sdk:99.0.0Nov 3, 2025
npmint_affirm_controllers:99.0.0Nov 3, 2025
npmfrontend-buenaspracticas:100.9.9Nov 3, 2025
npmctflibxmljs2:0.30.1Nov 3, 2025

Secure Your Open Source Dependencies against Vulnerabilities and Malicious Code

Malware isn’t just a theoretical risk anymore, it’s already hiding in public packages. With Xygeni’s Early Malware Detection, you can reduce exposure by catching threats as soon as they’re published, before they reach your pipeline.

Our real-time scanning and prioritization engine continuously monitors public registries like npm and PyPI. Malicious packages are blocked, flagged, and ranked based on impact, so you know exactly what needs fixing, and when. Whether it’s typosquatting, dependency confusion, or credential stealers, we help your team stay ahead.

If you want full visibility into weekly and monthly findings, check the complete Malicious Code Digest.

Stay secure. Stay fast. Stay in control with Xygeni.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
7-day free trial
No credit card required

Secure your Software Development and Delivery

with Xygeni Product Suite