Malicious Code Digest September Recap

Malicious Code Digest Monthly Recap: September

Welcome to the September edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed 104 malicious packages across npm and PyPI, tracked across four weekly digests.

September was defined by three converging trends: campaigns that carried straight over from August and kept going despite takedowns; dependency confusion at scale, with dozens of packages claiming inflated version numbers like 99.0.0 and 19999.x to hijack private namespaces; and a clear move toward the plugin and automation ecosystems developers trust with privileged access, such as Strapi, n8n and MCP.

Among the most notable campaigns documented this month:

  • The self-deleting anti-proctoring operator returned on September 1, with amicat, bmcat, eyevox and moidevh confirmed alongside two new names from the same stem, moidevk and moidevl.
  • Baileys, the WhatsApp Web API library impersonated throughout August, stayed under attack: cloud-baileys reached versions 1.1.37 and 1.1.38 in the first week and 1.1.41 by September 19, making it one of the longest-running impersonations we have tracked.
  • A 21-package campaign (September 15 to 17) published fake Strapi plugins under the “meeb” tag, all at the identical version 3.6.8, alongside companion packages with names like os-info-meeb322k and fs-pwn-meeb322k.
  • A single package, @nimbusedge/auth, shipped 39 versions in one day (September 11), all numbered 19999.x so they would outrank any legitimate internal version.
  • Dependency-confusion packages bearing corporate and internal-sounding names appeared every week: etoro-cashout, etoro-analytics and etoro-aggregator (September 11), concierge-sdk at 99.99.99 (September 13), @traktis/core (September 17), and @dbbhk/ui-components, @siriusbeyond/* and @alphaspace/core at 99.x in the last week of the month.
  • The “siriusbeyond” operator started with a single unscoped package on September 20 and came back four days later as a scoped family (@siriusbeyond/auth, /ui, /utils), the same brand dressed as an internal package set.
  • Fake n8n workflow nodes recurred through the month, including n8n-nodes-sysdiag2, n8n-nodes-buildcheck and n8n-nodes-data-transformer-utils, continuing a pattern first seen in August.
  • An MCP client, mcp-consultasdeveiculos-client, was published in three versions on a single day (September 4), a reminder that the AI tooling layer is now part of the same supply chain.
  • Six numbered copies of simple-date-formatter-new-* (11 to 16) were published on September 25, a scripted burst built to test which names get through.

The defining pattern of September: attackers are no longer only borrowing trusted names, they are borrowing trusted positions. Plugins, workflow nodes, MCP clients and private package namespaces all run with more access than a typical dependency, and they are exactly where September’s campaigns concentrated.

Below is a summary of what we found. You can see all four weeks’ data disclosed in full detail at the Malicious Code Digest index.

Week 5: 4 Packages Discovered

EcosystemPackageDate
npm@alphaspace/core:99.0.1September 26, 2026
npm@alphaspace/core:99.0.2September 26, 2026
npm@alphaspace/core:99.0.3September 26, 2026
npmcma-self-hosted-sandbox-cf:1.0.0September 26, 2026

Week 4: Over 24 Packages Discovered

EcosystemPackageConfirmed
npmtest890-auth:1.0.0Sep 18, 2026
npmbulk-add-sdk:1.99.99Sep 19, 2026
npmcloud-baileys:1.1.41Sep 19, 2026
npmbyted-commerce-materials:1.0.0Sep 20, 2026
npmmy-auto-follow:1.0.7Sep 20, 2026
npmsiriusbeyond:1.0.0Sep 20, 2026
npmsysverify:2.0.10Sep 22, 2026
npmn8n-nodes-data-transformer-utils:1.0.0Sep 23, 2026
npmtake-home-caller-id:1.0.1Sep 23, 2026
npm@dbbhk/ui-components:99.0.0Sep 24, 2026
npm@siriusbeyond/auth:99.0.0Sep 24, 2026
npm@alphaspace/core:99.0.2Sep 25, 2026
npmsimple-date-formatter-new-11:1.0.0Sep 25, 2026

Week 3: Over 81 Packages Discovered

EcosystemPackageConfirmed
pypilucy-python-script-2030:0.1.1Sep 11, 2026
npm@nimbusedge/auth:19999.x (39 versions)Sep 11, 2026
npmetoro-cashout:99.0.2Sep 11, 2026
npmetoro-analytics:99.0.2Sep 11, 2026
pypiaitextkit-py:0.1.1Sep 11, 2026
npmnoblox-asset.js:7.4.0Sep 12, 2026
npmconcierge-sdk:99.99.99Sep 13, 2026
pypidarkglitch:1.4.4Sep 15, 2026
npmfs-pwn-meeb322k:1.0.0Sep 15, 2026
npmstrapi-plugin-os-info-meeb322k:3.6.8Sep 15, 2026
npmn8n-nodes-sysdiag2:2.0.2Sep 15, 2026
npmn8n-nodes-buildcheck:1.0.0Sep 15, 2026
npmcsa-mfa:1.1.15Sep 16, 2026
npmstrapi-plugin-tryccresh-meeb:3.6.8Sep 16, 2026
npm@traktis/core:99.99.2Sep 17, 2026

Week 2: 13 Packages Discovered

EcosystemPackageDate
pypisyswatch:1.0.0September 07, 2026
pypisamaki:0.4.9September 07, 2026
composerslimfit/slimbase:2.0September 07, 2026
composerslimfit/formbase:1.2September 07, 2026
composergcform/formhelper:1.2September 07, 2026
npmcloud-baileys:1.1.39September 07, 2026
npmalloy-graphql:1.0.1September 08, 2026
npm@umschool/platform:999.0.0September 10, 2026
npmtwilio-hackerone-poc-b8f21a:1.0.0September 10, 2026
npmtwilio-hackerone-poc-b8f21a:1.0.1September 10, 2026
npmcloud-baileys:1.1.40September 11, 2026
pypidarkglitch:1.4.4September 11, 2026
pypidarkglitch:1.4.5September 11, 2026

Week 1: 18 Packages Discovered

EcosystemPackageConfirmed
npmamicat:1.0.0Sep 01, 2026
npmbmcat:2.0.9Sep 01, 2026
npmeyevox:1.0.0Sep 01, 2026
npmmoidevh:1.0.0Sep 01, 2026
npmmoidevk:1.0.0Sep 01, 2026
npmmoidevl:1.0.0Sep 01, 2026
pypisyswatch:1.0.0Sep 02, 2026
npmcloud-baileys:1.1.37Sep 02, 2026
npm@stellarshift/token-units:1.0.3Sep 02, 2026
npm@stellarshift/evm-address-kit:1.0.3Sep 02, 2026
npm@stellarshift/abi-tools:1.0.3Sep 02, 2026
npm@stellarshift/chain-metadata:1.0.3Sep 02, 2026
npm@a23842/dsh-notifier:0.1.0Sep 03, 2026
pypisamaki:0.4.9Sep 04, 2026
npmcloud-baileys:1.1.38Sep 04, 2026
npmmcp-consultasdeveiculos-client:0.1.1Sep 04, 2026
npmmcp-consultasdeveiculos-client:0.1.0Sep 04, 2026
npmmcp-consultasdeveiculos-client:0.0.2Sep 04, 2026

From Baileys to Strapi: What September’s Supply Chain Attacks Reveal

The campaigns above show attackers moving up the trust chain. A library impersonation that has now survived two months of takedowns, dependency-confusion packages inflating their version numbers to outrank private namespaces, and fake Strapi plugins, n8n nodes and MCP clients built to run where developers grant the most access: all of it lands in real SDLCs every week, often installed by automated tooling before any human reads the package name.

Xygeni’s malware detection and CI/CD and supply chain security give organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. MEW, Xygeni’s malware engine, detects malicious packages before a signature exists, across npm, PyPI, OpenVSX and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.

Every finding is automatically prioritized by exploitability, reachability, and business impact, so your team focuses on what actually needs fixing, not noise.

Explore every malicious package and campaign validated by the Xygeni Security Team in the Malicious Code Digest.

Stay secure. Stay fast. Stay in control with Xygeni.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
Get your Free Account.
No credit card required.

Secure your software development and delivery

with Xygeni Product Suite