MALICIOUS CODE OCTOBER

Malicious Code Digest Monthly Recap: October

Welcome to the latest edition of the Xygeni Malicious Code Digest (Monthly Edition). Once again, our security teams have been diving deep into real package data to spot what traditional tools often miss. The goal? Catch and block malicious packages before they land in your codebase or pipeline.

Over the past few weeks, we’ve confirmed over 280 malicious packages spreading across npm and PyPI. Many used advanced tactics like typosquatting, dependency confusion, and data exfiltration, all designed to slip past automated checks and compromise your environment.

This monthly update is part of our ongoing malware report, where we publish weekly findings, confirm new threats, and help DevSecOps teams stay ahead. If you want full context across every malicious package we’ve analyzed, make sure to explore the complete malicous code digest here.

Week 4: Over 124 Packages Discovered

Ecosystem Package Date
npm@adobe/helix-rum-js:2.13.6Oct 21, 2025
npm@agent-velo/era:0.1.0Oct 21, 2025
npm@ledgerhq/live-common:34.52.0-nightly.0Oct 21, 2025
npm@shopify.com/shopifyql-parser:3.999.9Oct 20, 2025
npmai-protocol:3.0.0Oct 20, 2025
npmcpilot-coding-assistant:1.0.7Oct 21, 2025
npmiwf-ant-design-draggable-modal:1.1.15Oct 24, 2025
npmmediapipe:1.3.5Oct 23, 2025
npmporscheofficial:2.9.9Oct 24, 2025
pypipdfdancer-client-python:0.2.11Oct 22, 2025

Week 3: Over 77 Packages Discovered

Ecosystem Package Date
npm@bgrc/kyc-theme:9000.0.2Oct 14, 2025
npm@bgrc/kyc-theme:9000.0.1Oct 14, 2025
npm@xyuzu.js/wb:1.0.0Oct 16, 2025
npmstack-ui-elements:1.0.0Oct 17, 2025
npm@chahuadev/framework:1.1.2Oct 14, 2025
npmmeta-boost-v1:2.1.1Oct 14, 2025
npmnomicswarm:1.1.0Oct 14, 2025
npmnomicswarm:1.1.1Oct 14, 2025
npmnomicswarm:1.1.2Oct 14, 2025
npm@mahdiar/caniuse-mcp:1.1.0Oct 14, 2025

Week 2: Over 55 Packages Discovered

Ecosystem Package Date
npmstack-ui-elements:1.0.0Oct 6, 2025
npmkn-nf-iso-properties-kn1:99.87.31Oct 6, 2025
npmeslint-plugin-paysafe:6.2.6Oct 7, 2025
npmwinston-logger-pro:1.1.1Oct 7, 2025
npmmerchantauxiliaryserv:1.0.0Oct 7, 2025
npmwinston-logger-pro:1.1.0Oct 7, 2025
npmgestion-usuarios:2.0.0Oct 7, 2025
npmincommincentives:2.2.0Oct 7, 2025
npmincommincentives:2.2.1Oct 7, 2025
npmoxrvxaslllcaj:1.0.0Oct 7, 2025

Week 1: Over 25 Packages Discovered

Ecosystem Package Confirmed By Date
npmcom.unity.device-simulator.devices:32.6.3RegistryOct 2, 2025
npm@cryptochords/shared:1.0.2RegistrySep 29, 2025
npmvusd-lib:1.0.0RegistrySep 29, 2025
npmkreme-crypto:0.0.1RegistrySep 29, 2025
pypijesse-xniu:1.0.1RegistrySep 30, 2025
npmcom.unity.device-simulator.devices:10.1.4RegistryOct 2, 2025
npmmshops-seo-ui:1.1.4RegistryOct 1, 2025
npmdawid-insecure-npm:1.0.0XygeniSep 29, 2025
npm@roayaiicsis/ui-library:2.0.0RegistrySep 29, 2025
npmcom.unity.device-simulator.devices:31.6.3RegistryOct 2, 2025

Secure Your Open Source Dependencies against Vulnerabilities and Malicious Code

Malware isn’t just a theoretical risk anymore, it’s already hiding in public packages. With Xygeni’s Early Malware Detection, you can reduce exposure by catching threats as soon as they’re published, before they reach your pipeline.

Our real-time scanning and prioritization engine continuously monitors public registries like npm and PyPI. Malicious packages are blocked, flagged, and ranked based on impact, so you know exactly what needs fixing, and when. Whether it’s typosquatting, dependency confusion, or credential stealers, we help your team stay ahead.

If you want full visibility into weekly and monthly findings, check the complete Malicious Code Digest.

Stay secure. Stay fast. Stay in control with Xygeni.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
7-day free trial
No credit card required

Secure your Software Development and Delivery

with Xygeni Product Suite