Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm and PyPI. This week was no exception.
We confirmed over 200 malicious packages between July 4 and July 10, 2026, across npm and PyPI, with several campaigns continuing from previous weeks and significant new activity emerging.
The largest new campaign this week came from the @wagni_bot scope, which published dozens of packages impersonating SDKs and agents for major crypto and DeFi platforms, including Polymarket, Hyperliquid, MetaMask (typosquatted as metemask-sdk), OpenSea, Solana, Jupiter, Orca, Pump.fun, Binance, and Meteora. Versions climbed rapidly (1.0.0 through 1.2.0) across nearly 30 distinct package names in under three hours on July 10, a scale consistent with automated, templated publishing rather than manual campaigns.
The mcp-server-pg cluster confirmed over 20 versions on July 7 alone, targeting developers looking for a Postgres MCP server integration. The hello244a and debugcli families each published a steady stream of incremental versions throughout the week, continuing the pattern of disposable, rapidly-versioned packages designed to stay ahead of takedowns.
Two campaigns we’ve already covered in dedicated reports continued directly into this window. The forge-jsxy infostealer resurfaced again under zredis-typed:1.0.127 and pinokio-redis:1.0.127 (July 7), the fourth and fifth rename of the same toolchain we detailed in our forge-jsxy analysis. Separately, we confirmed the first versions of moon-uv and my-magic-uv-helper on PyPI (July 9), fake uv helper packages that install a passwordless JupyterLab server and expose it to the internet, the campaign we track as FauxUV.
The AI-tooling impersonation pattern from previous weeks also continued, with anthropic-toolkit, ai-sdk-helpers, openai-agents-helpers, @langgraphjs/toolkit, and ollama-helpers all shipping incremented versions on July 7, alongside the nolimit-agent campaign, which pushed four more versions (1.0.327 through 1.0.336) extending the Microsoft 365 device-code phishing framework documented in our DeviceDoor report.
This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats and provide actionable intelligence to help DevSecOps teams protect their pipelines before damage occurs. Let’s break down what we found this week and why it matters.
200+ Packages. One Week. Attackers Are Scaling Faster Than Ever.
This week’s digest reflects a jump in both volume and coordination. What used to be dozens of packages per week is now hundreds, and the campaigns behind them are increasingly automated: scoped crypto SDK impersonation at scale, MCP-server targeting, and the same infostealer toolchains resurfacing under new names days after takedown. The pattern holds: attackers publish faster than registries remove, and faster than a weekly scan can catch.
Xygeni Early Malware Warning monitors npm, PyPI, and other registries in real time, flagging threats at the moment of publication, before they reach a build, before an AI agent installs them autonomously, and before a passwordless JupyterLab server or a rebranded infostealer has a chance to execute. When @wagni_bot publishes nearly 30 crypto SDK packages in under three hours, or forge-jsxy republishes under a new name for the fifth time, detection that runs after the fact is already too late.
Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization needed to stay ahead of coordinated supply chain pressure, so your pipelines stay clean without slowing your teams down.





