MALICIOUS CODE 62

Xygeni Malicious Code Digest 62

Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm and PyPI. This time, we confirmed over 135 malicious packages, ranging from typosquatting and credential stealers to backdoored libraries designed to slip past basic scanners.

This weekly snapshot is part of our ongoing Malicious Code Digest, where we publish continuous findings, confirm emerging threats, and help DevSecOps teams protect their pipelines before damage is done. If you want full context across all confirmed packages and past incidents, be sure to check the full digest.

Let’s break down what we found this week and why it matters.

Ecosystem Package Date
npmmysqldbstool:1.0.4Feb 09, 2026
npm@acqui-calm-library/acqui-hero-carousel-section:999.99.999Feb 09, 2026
npmringcentral-google-drive-notification-add-in:2.2.2Feb 09, 2026
npmdate-fns-2:1.0.0Feb 09, 2026
npmredux-saga-task-cancel-rce:1.0.0Feb 09, 2026
npmteeseest:1.6.2Feb 09, 2026
npminternal-logger-embaby:9.9.10Feb 09, 2026
npm@xcxcxxx/gsap3:99.10.90Feb 09, 2026
npmbdf-server-clone:1.0.0Feb 09, 2026
npmreact-native-kraken-oauth:1.0.1Feb 09, 2026
npmmysqldbstool:1.0.5Feb 09, 2026
npmmysqldbtool:1.0.3Feb 09, 2026
npmmeta-api-boostx-v2-pro:1.0.1-proFeb 09, 2026
npm@web-ib/chevre:9000.0.0Feb 09, 2026
npm@eqder/bird:14.0.0Feb 09, 2026
pypidonotinstall:1.0Feb 09, 2026
npmfrontend-buenaspracticas:99.9.9Feb 09, 2026
npmlbank-connector-nodejs:2.0.0Feb 09, 2026
npm@spectraltest/loglevel:2.5.0Feb 09, 2026
npmspectral-wraith:1.0.0Feb 09, 2026
npmsupermoy1:0.30.1Feb 09, 2026
npmsupervot5:0.30.1Feb 09, 2026
npmfinalmoyloyt:0.30.1Feb 09, 2026
npmxmljs2bank:0.30.2Feb 09, 2026
npmsuperbankbackdoor:1.0.0Feb 09, 2026
npmsuperbankbackdoor:0.30.1Feb 09, 2026
npmcachelogger:0.30.1Feb 09, 2026
npmmegadepsexploit:0.30.1Feb 09, 2026
npmmegaexploitvorkemol:0.30.1Feb 09, 2026
npmmegaexploitvorkemol1:0.30.1Feb 09, 2026
npm@!not/ui:0.0.1Feb 09, 2026
npm@jaspal.dhillon/corplib:999.0.0Feb 09, 2026
npmcorplib-internal:999.0.0Feb 09, 2026
npmkkkarem:2.0.0Feb 09, 2026
npmkkkaremn:1.0.0Feb 09, 2026
npmkaremz:1.0.0Feb 09, 2026
npmkaremz:2.0.0Feb 09, 2026
npmkaremzz:2.0.0Feb 09, 2026
npmkaremz:5.0.0Feb 09, 2026
npmkkkaremn:7.0.0Feb 09, 2026
npmkkkaremn:8.0.0Feb 09, 2026
npmkkkaremnn:11.0.0Feb 09, 2026
npmkkkaremnnn:1.0.0Feb 09, 2026
npmkarem4:1.0.0Feb 09, 2026
npmkarem3:1.0.0Feb 09, 2026
npmkarem3:2.0.0Feb 09, 2026
npmkarem5:1.0.0Feb 09, 2026
npmkarem7:1.0.0Feb 09, 2026
npmkarem8:1.0.0Feb 09, 2026
npmkarem9:1.0.0Feb 09, 2026
npmkarem10:1.0.0Feb 09, 2026
npmkaremm1:1.0.0Feb 09, 2026
npmkarem6:1.0.0Feb 09, 2026
npmkarem2:1.0.0Feb 09, 2026
npmkaremm3:1.0.0Feb 09, 2026
npmkaremm4:1.0.0Feb 09, 2026
npmkaremm6:1.0.0Feb 09, 2026
npmkaremm5:1.0.0Feb 09, 2026
npmkaremm7:1.0.0Feb 09, 2026
npmkaremm2:1.0.0Feb 09, 2026
npmkarem1:1.0.0Feb 09, 2026
npmmonoping:1.0.6Feb 09, 2026
npmmonoping:1.0.3Feb 09, 2026
npmeslint-plugin-fuel-react:1.0.0Feb 09, 2026
npmeslint-plugin-fuel-react:1.0.1Feb 09, 2026
npmeslint-plugin-fuel-react:1.0.2Feb 09, 2026
npmmoltbot-termux:2026.1.27Feb 09, 2026
pypiiflow-mcp-dropbox-mcp-server-dash:0.1.0Feb 09, 2026
pypiiflow-mcp-dropbox-mcp-server-dash:0.1.1Feb 09, 2026
npmmoltbot-termux:2026.1.28-4Feb 09, 2026
pypibaguette-agent:0.1.0Feb 09, 2026
pypicnhkmcp:2.3.1Feb 09, 2026
npm@anthropic-field/cli:0.3.1Feb 06, 2026
npm@anthropic-field/cli:0.2.0Feb 06, 2026
npm@anthropic-field/cli:0.3.0Feb 06, 2026
npm@anthropic-field/cli:0.2.1Feb 06, 2026
npm@anthropic-field/cli:0.1.0Feb 06, 2026
npm@qingchencloud/openclaw-zh:2026.1.30-nightly.202602012355Feb 06, 2026
npm@qingchencloud/openclaw-zh:2026.2.1-zh.3Feb 06, 2026
npm@qingchencloud/openclaw-zh:2026.1.30-nightly.202602011756Feb 06, 2026
npm@qingchencloud/openclaw-zh:2026.1.30-nightly.202602012258Feb 06, 2026
npmopenclaw-cn:2026.1.31-beta.0Feb 06, 2026
npmopenclaw-cn:2026.1.31-beta.1Feb 06, 2026
npm@mmarena/mcp:0.1.4Feb 09, 2026
npm@mmarena/mcp:0.1.5Feb 09, 2026
npm@mmarena/mcp:0.1.6Feb 09, 2026
npmopenclawapi:1.3.39Feb 09, 2026
npmopenclawapi:1.3.45Feb 09, 2026
npm@qingchencloud/openclaw-zh:2026.2.2-3-nightly.202602050319Feb 09, 2026
npm@qingchencloud/openclaw-zh:2026.2.2-3-nightly.202602050507Feb 09, 2026
npm@qingchencloud/openclaw-zh:2026.2.3-1-nightly.202602050927Feb 09, 2026
npm@qingchencloud/openclaw-zh:2026.2.3-1-nightly.202602070455Feb 09, 2026
npm@qingchencloud/openclaw-zh:2026.2.6-3-nightly.202602071329Feb 09, 2026
npm@qingchencloud/openclaw-zh:2026.2.6-3-nightly.202602071903Feb 09, 2026
npm@qingchencloud/openclaw-zh:2026.2.6-3-nightly.202602080725Feb 09, 2026
npm@qingchencloud/openclaw-zh:2026.2.6-3-nightly.202602081330Feb 09, 2026
npm@qingchencloud/openclaw-zh:2026.2.6-3-nightly.202602081403Feb 09, 2026
npm@qingchencloud/openclaw-zh:2026.2.6-3-nightly.202602091214Feb 09, 2026
npm@qingchencloud/openclaw-zh:2026.2.9-nightly.202602101840Feb 11, 2026
npm@commonschema/blackstone-core:0.2.2-alphaFeb 09, 2026
npmopenclaw-pro:2026.2.35Feb 09, 2026
npmopenclaw-pro:2026.2.43Feb 09, 2026
npmopenclaw-pro:2026.2.47Feb 09, 2026
npmopenclaw-pro:2026.2.7Feb 09, 2026
npmopenclaw-pro:2026.2.7-1Feb 09, 2026
npmopenclaw-pro:2026.2.9Feb 09, 2026
npmopenclaw-pro:2026.2.96Feb 09, 2026
npmcryptoclaw:1.0.3Feb 09, 2026
npm@aruna-yoocrm/agiagent:2026.1.38Feb 09, 2026
npmagiagent-dev:2026.1.41Feb 09, 2026
npmopenclaw-cn:0.1.4Feb 09, 2026
npmselfbot-lofy:1.0.2Feb 09, 2026
npmselfbot-lofy:1.0.3Feb 09, 2026
npmselfbot-lofy:1.0.4Feb 09, 2026
npmselfbot-lofy:1.0.5Feb 09, 2026
npmselfbot-lofy:1.0.6Feb 09, 2026
npmselfbot-lofy:1.0.7Feb 09, 2026
npmselfbot-lofy:1.0.8Feb 09, 2026
npmselfbot-lofy:1.0.9Feb 09, 2026
npmselfbot-lofy:1.2.0Feb 09, 2026
npmselfbot-lofy:1.2.1Feb 09, 2026
npmselfbot-lofy:1.2.3Feb 09, 2026
npmpressclaw:0.3.0Feb 09, 2026
npm@poolzin/pool-bot:2026.1.38Feb 09, 2026
npm@zzedbot/yunzhijia:1.0.2Feb 11, 2026
npmcontact-button-podlet:5.8.5Feb 11, 2026
npmsearch-savedsearch-podlet:5.4.5Feb 11, 2026
npmsearch-newfrontier-podlet:3.1.5Feb 11, 2026
npmstatic-content-cannabis:999.0.0Feb 11, 2026
npm@iflow-mcp/bacoco-ai-expert-workflow-mcp:2.3.2Feb 11, 2026
pypijsonconfig-utils:1.0.10Feb 11, 2026
pypijsonconfig-utils:1.0.11Feb 11, 2026
npmether-lint:5.9.0Feb 12, 2026
npmlibjs-cqs:90.9.0Feb 12, 2026
npmcollabs-merchants:99.9.12Feb 12, 2026

Secure Your Open Source Dependencies against Vulnerabilities and Malicious Code

Minimize risks and protect your applications from malicious packages with Xygeni Early Malware Detection. Prioritize and address the vulnerabilities that matter most. Our comprehensive solution offers real-time monitoring of your dependencies to detect and mitigate threats before they impact your software.

Managing open-source components in the current software development landscape is crucial due to the rising vulnerabilities and malicious code threats. Xygeni’s Open Source Security solution scans and blocks harmful packages upon publication, dramatically minimizing the risk of malware and vulnerabilities infiltrating your systems. Our comprehensive monitoring spans multiple public registries, ensuring all dependencies are scrutinized for safety and integrity. Xygeni enhances your team’s ability to maintain secure and reliable software projects by contextually prioritizing critical issues and facilitating streamlined remediation processes.

Xygeni uses multi-layered techniques to stop malicious code before it spreads. First of all, static code analysis detects obfuscation patterns, hidden payloads, and script abuse. In addition, behavioral sandboxing analyzes install hooks, runtime commands, and persistence tricks. Moreover, machine learning detection identifies zero-day npm malware and pypi malware variants missed by signature scanners. Finally, the Early Warning System monitors public repositories in real time, validates findings, and alerts DevOps teams immediately.

As a result, this combination ensures developers receive fast, actionable intelligence integrated directly into CI/CD workflows.

Why Developers Should Care About Malicious npm Packages

Modern threats rarely wait for runtime. For example, malicious npm packages often execute during installation, while pypi malicious packages hide token exfiltration or backdoors. Attackers:

  • Flip private GitHub repos to public to replicate them.
  • Exfiltrate credentials and secrets using encoded payloads.
  • Use obfuscated JavaScript loaders to deploy ransomware or botnets.

In fact, malicious open-source packages surged 156% in one year. Therefore, teams that rely only on delayed feeds or basic scanners fall behind.

What This Malware Report Tracks in npm and PyPI

This digest is the central hub for:

  • Confirmed malicious npm packages
  • Confirmed pypi malicious packages
  • Behavior-based detections of malicious code
  • Registry-confirmed incidents
  • Weekly and monthly malware report summaries
  • Historical changelog of all npm malware and pypi malware findings

In other words, it provides a single point of reference. The research team at Xygeni updates this page weekly with links to full technical analyses and GitHub IOCs.

How to Protect Against Malicious npm Packages and PyPI Malware

Because of this growing risk, organizations need strong defenses:

  • Enforce lockfile-only installs (npm ci) in CI/CD.
  • Additionally, scan dependencies pre-install with Xygeni’s Early Warning Engine.
  • Furthermore, block builds on malicious code signals using Guardrails.
  • Generate SBOMs to trace indirect dependencies and apply policies.
  • Above all, train developers to detect typosquatting, obfuscation, and suspicious install scripts.

Try Xygeni’s Malware Detection Tools

Xygeni delivers:

  • Real-time detection of malicious code, including backdoors, spyware, and ransomware.
  • In contrast to basic scanners, analysis across npm, PyPI, Maven, NuGet, RubyGems, and more.
  • Automatic build blocking when the malware report identifies risk.
  • Exploitability insights, maintainer reputation checks, and anomaly detection.
sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
7-day free trial
No credit card required

Secure your Software Development and Delivery

with Xygeni Product Suite