xygeni malicious code digest 78

Xygeni Malicious Code Digest 78

Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm and PyPI. This week was no exception.

We confirmed over 200 malicious packages between July 4 and July 10, 2026, across npm and PyPI, with several campaigns continuing from previous weeks and significant new activity emerging.

The largest new campaign this week came from the @wagni_bot scope, which published dozens of packages impersonating SDKs and agents for major crypto and DeFi platforms, including Polymarket, Hyperliquid, MetaMask (typosquatted as metemask-sdk), OpenSea, Solana, Jupiter, Orca, Pump.fun, Binance, and Meteora. Versions climbed rapidly (1.0.0 through 1.2.0) across nearly 30 distinct package names in under three hours on July 10, a scale consistent with automated, templated publishing rather than manual campaigns.

The mcp-server-pg cluster confirmed over 20 versions on July 7 alone, targeting developers looking for a Postgres MCP server integration. The hello244a and debugcli families each published a steady stream of incremental versions throughout the week, continuing the pattern of disposable, rapidly-versioned packages designed to stay ahead of takedowns.

Two campaigns we’ve already covered in dedicated reports continued directly into this window. The forge-jsxy infostealer resurfaced again under zredis-typed:1.0.127 and pinokio-redis:1.0.127 (July 7), the fourth and fifth rename of the same toolchain we detailed in our forge-jsxy analysis. Separately, we confirmed the first versions of moon-uv and my-magic-uv-helper on PyPI (July 9), fake uv helper packages that install a passwordless JupyterLab server and expose it to the internet, the campaign we track as FauxUV.

The AI-tooling impersonation pattern from previous weeks also continued, with anthropic-toolkit, ai-sdk-helpers, openai-agents-helpers, @langgraphjs/toolkit, and ollama-helpers all shipping incremented versions on July 7, alongside the nolimit-agent campaign, which pushed four more versions (1.0.327 through 1.0.336) extending the Microsoft 365 device-code phishing framework documented in our DeviceDoor report.

This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats and provide actionable intelligence to help DevSecOps teams protect their pipelines before damage occurs. Let’s break down what we found this week and why it matters.

Ecosystem Package Confirmed
pypiprocwire:5.2.3Jul 4, 2026
pypiprocwire:5.2.5Jul 4, 2026
pypiprocwire:5.2.6Jul 4, 2026
pypiprocwire:5.2.7Jul 4, 2026
npmneon-terminal:0.3.0Jul 4, 2026
npmnolimit-agent:1.0.327Jul 4, 2026
npmnolimit-agent:1.0.328Jul 4, 2026
npmnolimit-agent:1.0.331Jul 5, 2026
npmna-rony:1.1.2Jul 5, 2026
npmna-rony:1.1.3Jul 5, 2026
npmna-rony:1.1.4Jul 5, 2026
npmna-rony:1.1.5Jul 5, 2026
npmnolimit-agent:1.0.335Jul 5, 2026
npmnolimit-agent:1.0.336Jul 6, 2026
vscodeandroid-support-framework-vs:0.0.1Jul 6, 2026
npmnext-locomotive-init:1.0.1Jul 7, 2026
npmnext-locomotive-init:1.0.2Jul 7, 2026
npmnext-locomotive-init:1.0.3Jul 7, 2026
npmnext-locomotive-init:1.0.0Jul 7, 2026
npm@adobesign/as-dev-tools:99.9.9Jul 7, 2026
npm@langgraphjs/toolkit:1.2.13Jul 7, 2026
npmai-sdk-helpers:1.4.5Jul 7, 2026
npmanthropic-toolkit:1.3.1Jul 7, 2026
npmmcp-server-pg:0.1.0Jul 7, 2026
npmmcp-server-pg:0.2.1Jul 7, 2026
npmmcp-server-pg:0.3.0Jul 7, 2026
npmmcp-server-pg:0.3.1Jul 7, 2026
npmmcp-server-pg:0.6.0Jul 7, 2026
npmmcp-server-pg:0.8.0Jul 7, 2026
npmmcp-server-pg:1.0.0Jul 7, 2026
npmmcp-server-pg:1.1.0Jul 7, 2026
npmmcp-server-pg:1.1.1Jul 7, 2026
npmmcp-server-pg:1.2.0Jul 7, 2026
npmollama-helpers:1.2.3Jul 7, 2026
npmopenai-agents-helpers:1.3.3Jul 7, 2026
npmmcp-server-pg:0.1.1Jul 7, 2026
npmmcp-server-pg:0.1.2Jul 7, 2026
npmmcp-server-pg:0.1.3Jul 7, 2026
npmmcp-server-pg:0.2.0Jul 7, 2026
npmmcp-server-pg:0.4.0Jul 7, 2026
npmmcp-server-pg:0.5.0Jul 7, 2026
npmmcp-server-pg:0.7.0Jul 7, 2026
npmmcp-server-pg:0.9.0Jul 7, 2026
npmmcp-server-pg:1.0.1Jul 7, 2026
npmmcp-server-pg:1.2.1Jul 7, 2026
npmmcp-server-pg:1.2.2Jul 7, 2026
npmdebugcli:4.3.4Jul 7, 2026
npmdebugcli:4.3.5Jul 7, 2026
npmdebugcli:4.3.6Jul 7, 2026
npmdebugcli:4.3.8Jul 7, 2026
npmdebugcli:4.3.9Jul 7, 2026
npmdebugcli:4.4.1Jul 7, 2026
npmgen-ai-opt-in:99.0.2Jul 7, 2026
npmhello244a:1.0.10Jul 7, 2026
npmhello244a:1.0.12Jul 7, 2026
npmhello244a:1.0.18Jul 7, 2026
npmhello244a:1.0.19Jul 7, 2026
npmhello244a:1.0.20Jul 7, 2026
npmhello244a:1.0.21Jul 7, 2026
npmhello244a:1.0.22Jul 7, 2026
npmhello244a:1.0.23Jul 7, 2026
npmhello244a:1.0.27Jul 7, 2026
npmhello244a:1.0.30Jul 7, 2026
npmhello244a:1.0.35Jul 7, 2026
npmhello244a:1.0.37Jul 7, 2026
npmhello244a:1.0.38Jul 7, 2026
npmhello244a:1.0.6Jul 7, 2026
npmhello244a:1.0.7Jul 7, 2026
npmhello244a:1.0.8Jul 7, 2026
npmhello244a:1.0.9Jul 7, 2026
npmpinokio-redis:1.0.127Jul 7, 2026
npmzredis-typed:1.0.127Jul 7, 2026
npmpaperclip-host-utils:1.0.6Jul 7, 2026
npmrony-test:99.9.9Jul 8, 2026
npmzluri-ad-connector:9.9.9Jul 8, 2026
npmthunder-rony:99.9.9Jul 8, 2026
npmnext-locomotive-init:1.0.4Jul 8, 2026
npmronyfortest:99.9.9Jul 8, 2026
npmkarem-dp:99.9.9Jul 8, 2026
npmna-rony-test-karem:99.9.9Jul 8, 2026
npmna-rony-test:99.9.9Jul 8, 2026
npmna-rony:99.9.9Jul 8, 2026
npmnam-os-a-man:99.9.9Jul 8, 2026
npmrony-testing:99.9.9Jul 8, 2026
pypimy-magic-uv-helper:0.0.1Jul 9, 2026
npmdependency_confusions:99.9.9Jul 9, 2026
npmplayerdata-core:9.9.1Jul 9, 2026
pypimoon-uv:0.0.1Jul 9, 2026
pypimoon-uv:0.0.2Jul 9, 2026
pypimoon-uv:0.0.3Jul 9, 2026
npm@playerdata-internal/playerdata-core:12.1.20Jul 9, 2026
npm@playerdata-internal/playerdata-core:9999.99.20Jul 9, 2026
npmes6-codify:1.0.1Jul 9, 2026
pypimoon-uv:0.0.5Jul 9, 2026
npmes6-codify:1.1.0Jul 9, 2026
npmes6-codify:1.2.0Jul 9, 2026
npmes6-codify:1.3.0Jul 9, 2026
pypimoon-uv:0.0.6Jul 9, 2026
npmes6-codify:1.4.0Jul 9, 2026
pypimoon-uv:0.0.7Jul 9, 2026
pypimoon-uv:0.0.8Jul 9, 2026
pypimoon-uv:0.0.9Jul 9, 2026
npmes6-codify:2.0.0Jul 9, 2026
npmes6-codify:2.1.0Jul 9, 2026
pypimoon-uv:0.0.10Jul 9, 2026
pypimoon-uv:0.0.12Jul 9, 2026
pypimoon-uv:0.0.13Jul 9, 2026
pypimoon-uv:0.0.14Jul 9, 2026
pypimoon-uv:0.0.15Jul 9, 2026
pypimoon-uv:0.0.16Jul 9, 2026
npmsliftutils:1.7.4Jul 9, 2026
npmsliftutils:1.7.3Jul 9, 2026
npmairkey-mfa-react:29.1.1Jul 9, 2026
npmairkey-mfa-react:35.1.1Jul 9, 2026
npmairkey-mfa-react:36.1.1Jul 9, 2026
npmn8n-nodes-mcputils:0.1.4Jul 9, 2026
npmrio-design-tokens:99.99.99Jul 9, 2026
npmnone123s:0.1.2Jul 9, 2026
npmnone123s:0.1.3Jul 9, 2026
npmnone123s:1.1.2Jul 9, 2026
npmnone123s:1.1.3Jul 9, 2026
npmnone123s:1.1.6Jul 9, 2026
npmsearchresults:999.0.0Jul 10, 2026
npmcursed-ecto-d3ab00:1.0.0Jul 10, 2026
npm@wagni_bot/hyperliquid-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/metemask-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/polymarket-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/web3-agent:1.0.0Jul 10, 2026
npm@wagni_bot/bsc-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/eth-agent:1.0.0Jul 10, 2026
npm@wagni_bot/opensea-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/polygon-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/eth-agent:1.1.0Jul 10, 2026
npm@wagni_bot/metemask-sdk:1.1.0Jul 10, 2026
npm@wagni_bot/polygon-sdk:1.1.0Jul 10, 2026
npm@wagni_bot/bsc-sdk:1.1.0Jul 10, 2026
npm@wagni_bot/hyperliquid-sdk:1.1.0Jul 10, 2026
npm@wagni_bot/opensea-sdk:1.1.0Jul 10, 2026
npm@wagni_bot/polymarket-sdk:1.1.0Jul 10, 2026
npm@wagni_bot/web3-agent:1.1.0Jul 10, 2026
npm@wagni_bot/hyperliquid-sdk:1.1.1Jul 10, 2026
npm@wagni_bot/metemask-sdk:1.1.1Jul 10, 2026
npm@wagni_bot/opensea-sdk:1.1.1Jul 10, 2026
npm@wagni_bot/polygon-sdk:1.1.1Jul 10, 2026
npm@wagni_bot/web3-agent:1.1.1Jul 10, 2026
npm@wagni_bot/bsc-sdk:1.1.1Jul 10, 2026
npm@wagni_bot/eth-agent:1.1.1Jul 10, 2026
npm@wagni_bot/opensea-sdk:1.1.3Jul 10, 2026
npm@wagni_bot/polymarket-sdk:1.1.1Jul 10, 2026
npm@wagni_bot/bsc-sdk:1.1.3Jul 10, 2026
npm@wagni_bot/hyperliquid-sdk:1.1.3Jul 10, 2026
npm@wagni_bot/metemask-sdk:1.1.3Jul 10, 2026
npm@wagni_bot/web3-agent:1.1.3Jul 10, 2026
npm@wagni_bot/eth-agent:1.1.3Jul 10, 2026
npm@wagni_bot/metemask-sdk:1.1.4Jul 10, 2026
npm@wagni_bot/polygon-sdk:1.1.3Jul 10, 2026
npm@wagni_bot/polymarket-sdk:1.1.3Jul 10, 2026
npm@wagni_bot/polymarket-sdk:1.1.4Jul 10, 2026
npm@wagni_bot/bsc-sdk:1.1.4Jul 10, 2026
npm@wagni_bot/eth-agent:1.1.4Jul 10, 2026
npm@wagni_bot/polygon-sdk:1.1.4Jul 10, 2026
npm@wagni_bot/web3-agent:1.1.4Jul 10, 2026
npm@wagni_bot/hyperliquid-sdk:1.1.4Jul 10, 2026
npm@wagni_bot/opensea-sdk:1.1.4Jul 10, 2026
npmtesting-d3do:99.9.9Jul 10, 2026
npm@wagni_bot/binance-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/web3-toolkit:1.0.0Jul 10, 2026
npm@wagni_bot/jupiter-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/orca-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/pumpfun-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/solana-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/hyperliquid-sdk:1.1.5Jul 10, 2026
npm@wagni_bot/metemask-sdk:1.1.5Jul 10, 2026
npm@wagni_bot/opensea-sdk:1.1.5Jul 10, 2026
npm@wagni_bot/polygon-sdk:1.1.5Jul 10, 2026
npm@wagni_bot/polymarket-sdk:1.1.5Jul 10, 2026
npm@wagni_bot/bsc-sdk:1.1.5Jul 10, 2026
npm@wagni_bot/eth-agent:1.1.5Jul 10, 2026
npm@wagni_bot/ethereum-wallet:1.0.0Jul 10, 2026
npm@wagni_bot/web3-agent:1.1.5Jul 10, 2026
npm@wagni_bot/web3-agent:1.2.0Jul 10, 2026
npm@wagni_bot/metemask-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/opensea-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/polygon-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/polymarket-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/bsc-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/hyperliquid-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/jupiter-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/orca-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/solana-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/eth-agent:1.2.0Jul 10, 2026
npm@wagni_bot/ethereum-wallet:1.2.0Jul 10, 2026
npm@wagni_bot/meteora-sdk:1.0.0Jul 10, 2026
npm@wagni_bot/pumpfun-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/binance-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/meteora-sdk:1.2.0Jul 10, 2026
npm@wagni_bot/web3-toolkit:1.2.0Jul 10, 2026
npmclient-cookies-agent:99.9.6Jul 10, 2026
npmclient-cookies-agent:99.9.5Jul 10, 2026
npmnonenull1:1.2.0Jul 10, 2026
npmnonenull1:1.3.0Jul 10, 2026
npmnonenull1:1.5.0Jul 10, 2026
npmnonenull1:1.5.2Jul 10, 2026
npmnonenull1:1.6.0Jul 10, 2026
npmfury_frontend-andes-ui:99.9.5Jul 10, 2026
pypimoon-uv:0.0.17Jul 10, 2026
pypimoon-uv:0.0.18Jul 10, 2026
pypimoon-uv:0.0.19Jul 10, 2026
npmes6-codify:2.2.0Jul 10, 2026

200+ Packages. One Week. Attackers Are Scaling Faster Than Ever.

This week’s digest reflects a jump in both volume and coordination. What used to be dozens of packages per week is now hundreds, and the campaigns behind them are increasingly automated: scoped crypto SDK impersonation at scale, MCP-server targeting, and the same infostealer toolchains resurfacing under new names days after takedown. The pattern holds: attackers publish faster than registries remove, and faster than a weekly scan can catch.

Xygeni Early Malware Warning monitors npm, PyPI, and other registries in real time, flagging threats at the moment of publication, before they reach a build, before an AI agent installs them autonomously, and before a passwordless JupyterLab server or a rebranded infostealer has a chance to execute. When @wagni_bot publishes nearly 30 crypto SDK packages in under three hours, or forge-jsxy republishes under a new name for the fifth time, detection that runs after the fact is already too late.

Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization needed to stay ahead of coordinated supply chain pressure, so your pipelines stay clean without slowing your teams down.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
Get your Free Account.
No credit card required.

Secure your Software Development and Delivery

with Xygeni Product Suite