Malicious Code Digest 82

Xygeni Malicious Code Digest 82

Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 206 malicious packages between July 31 and August 7, 2026, led by a wave of malware openly branded after known AI-attack tools, and a dependency-confusion cluster impersonating cryptocurrency wallet libraries.

The most attention-grabbing find: wormgpt-cli on npm, nine versions published in rapid succession on August 7, alongside a companion package, gpt-terminal-cli, published the same day. The name is a direct reference to WormGPT, a real dark-LLM tool marketed to cybercriminals for phishing and malware generation, suggesting the package is trading on the brand recognition of an actual attacker tool rather than hiding behind a neutral name.

A separate cluster targeted cryptocurrency infrastructure directly: nine packages on npm impersonating real wallet and signing libraries (ledger-lib, trezor-lib, bip32-js, ethers-lib, python-bitcoinlib, ckcc-protocol, hwi-lib, mnemonic-utils, ethereum-sign-utils), all confirmed within the same window on August 5, a textbook dependency-confusion play aimed at crypto and Web3 developers pulling in what look like standard signing utilities.

The markscan, akrai, and iphouse lookalike cluster we flagged last week kept growing, with several more versions confirmed July 31 through August 1. That same window also produced a more serious find: the beaver-ui-* and accounts-* cluster confirmed August 1 turned out to be QuietPolyfill, a three-stage dropper disguised as internal UI component and utility packages. The payload triggers on require(), not an install script, so --ignore-scripts does not stop it. Nineteen of the twenty package names were unpublished by the operator within hours of detection; one was republished under a different account the next day, and the delivery infrastructure was still live when we published our full analysis.

This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats and provide actionable intelligence to help DevSecOps teams protect their pipelines before damage occurs.

Ecosystem Package Confirmed
npmai-backup-script:1.0.0Jul 31, 2026
npmadpanel-core:1.0.0Jul 31, 2026
npmallurectl:1.0.0Jul 31, 2026
npmattio-discover:1.0.0Jul 31, 2026
npmcapacitor-assets:1.0.0Jul 31, 2026
npmcommunity-published:1.0.0Jul 31, 2026
npmchaos-mcp:1.0.0Jul 31, 2026
npmgoldenflow-js:1.0.0Jul 31, 2026
npmgrok-oauth-mcp:1.0.0Jul 31, 2026
npmfast-csv-helper:1.0.0Jul 31, 2026
npmgtm-mcp-auth:1.0.0Jul 31, 2026
npmhazmat-cfr:1.0.0Jul 31, 2026
npmhit-mcp:1.0.0Jul 31, 2026
npmiac-scanner:1.0.0Jul 31, 2026
npmhomekit-mcp:1.0.0Jul 31, 2026
npminstall-native-host:1.0.0Jul 31, 2026
npmiwomm-mcp:1.0.0Jul 31, 2026
npmkip-mcp-http:1.0.0Jul 31, 2026
npmmaximumsats-mcp:1.0.0Jul 31, 2026
npmmcp-server-boilerplate:1.0.0Jul 31, 2026
npmpm-claude-skills-mcp:1.0.0Jul 31, 2026
npmpolyprompt:1.0.0Jul 31, 2026
npmrefbase-mcp:1.0.0Jul 31, 2026
npmsap-mcp-facilitator:1.0.0Jul 31, 2026
npmsap-mcp-config:1.0.0Jul 31, 2026
npmrouterbase-mcp:1.0.0Jul 31, 2026
npmsmart-npv-mcp:1.0.0Jul 31, 2026
npmsetup-codex:1.0.0Jul 31, 2026
npmparaglide-js:1.0.1Jul 31, 2026
npmai-backup-script:1.0.2Jul 31, 2026
npmcreate-remotion:0.0.3Jul 31, 2026
npmmarkscan-utils:1.0.0Aug 01, 2026
npmmarkscan-api:1.0.0Aug 01, 2026
npmakrai-report:1.0.0Aug 01, 2026
npmmarkscan-reports:1.0.0Aug 01, 2026
npmmarkscan-utils:1.0.0Aug 01, 2026
npmiphouse-core:1.0.0Aug 01, 2026
npmakrai-report-new:1.0.0Aug 01, 2026
npmmarkscan-api:1.0.0Aug 01, 2026
npmakrai-report:1.0.0Aug 01, 2026
npmiphouse-api:1.0.0Aug 01, 2026
npmiphouse:1.0.0Aug 01, 2026
npmmarkscan-core:1.0.0Aug 01, 2026
npmmarkscan-reports:1.0.0Aug 01, 2026
npmmarkscan:1.0.0Aug 01, 2026
npm@szc-ft/mcp-szcd-client:0.39.1Aug 01, 2026
npm@szc-ft/mcp-szcd-client:0.39.2Aug 01, 2026
npmfundraiserservicepp:1.7.0Aug 01, 2026
npmfundraiserservpp:1.9.0Aug 01, 2026
npmfundraiserservpp:2.0.0Aug 01, 2026
npmpage-navigation:1.0.1Aug 01, 2026
npmbasic-vite:1.0.0Aug 01, 2026
openvsxchiehyu/vscode-astyle:0.0.1Aug 01, 2026
openvsxspikespaz/vscode-smoothtype:0.0.1Aug 01, 2026
npmelectrode-ota-ui-app:99.0.0Aug 01, 2026
npmelectrode-ota-ui-app:99.0.1Aug 01, 2026
openvsxlego-education/ev3-micropython:0.0.1Aug 01, 2026
npmmessenger-style:1.0.1Aug 01, 2026
openvsxgeddski/macros:0.0.1Aug 01, 2026
openvsxbastienboutonnet/vscode-dbt:0.0.1Aug 01, 2026
openvsxtechnosophos/vscode-helm:0.0.1Aug 01, 2026
openvsxheaths/vscode-guid:0.0.1Aug 01, 2026
openvsxofhumanbondage/react-proptypes-intellisense:0.0.1Aug 01, 2026
openvsxdbankier/vscode-instant-markdown:0.0.1Aug 01, 2026
npmglia-functions-tools:0.2.1Aug 01, 2026
npmvscode-designer-14:14.0.1Aug 01, 2026
npmjobber-app-template-react:1.0.1Aug 01, 2026
npmtechnical-challenge:1.0.1Aug 01, 2026
npm@ks-video/kwai-player-web:9.1.2Aug 01, 2026
npmflydev:0.0.1Aug 01, 2026
openvsxnpxms/hide-gitignored:0.0.2Aug 01, 2026
openvsxmukundan/python-docs:0.0.3Aug 01, 2026
openvsxdrewbourne/vscode-remark-lint:0.0.3Aug 01, 2026
openvsxalex-chen/gitee-code-settings-sync:0.0.1Aug 01, 2026
openvsx365businessdevelopment/bdev-al-xml-doc:0.0.1Aug 01, 2026
openvsxalduncanson/react-hooks-snippets:0.0.1Aug 01, 2026
openvsxacademiadosdevs/javafx:0.0.1Aug 01, 2026
openvsxazurepolicy/azurepolicyextension:0.0.1Aug 01, 2026
openvsxbdznh/c-cpp-compile-run-windows:0.0.1Aug 01, 2026
openvsxbartmanabyss/amiga-debug:0.0.1Aug 01, 2026
openvsxbretdoyle/javascript-extensions-pack---js-essentials:0.0.1Aug 01, 2026
npmtest-dev-watch:0.1.0Aug 01, 2026
npmaedes_clusters:1.0.1Aug 01, 2026
npma.poltoradnev-package-c:6.1.12Aug 01, 2026
npmaccounts-timeline:9.6.12Aug 01, 2026
npmbcore-bravo-eslint-config:9.5.9Aug 01, 2026
npmbeaver-ui-drawer:9.4.10Aug 01, 2026
npmbeaver-ui-card-large:9.6.5Aug 01, 2026
npmbeaver-ui-actions-button:5.4.9Aug 01, 2026
npmarbocrate-sla-prober-arbocrate-sla-prober-core:7.5.9Aug 01, 2026
npmafisha-storybook-default:9.7.12Aug 01, 2026
npmboardwalk-js-tests:1.1.1Aug 01, 2026
npmbeaver-ui-drawer:9.4.11Aug 01, 2026
npmbeaver-ui-drawer:9.4.12Aug 01, 2026
npmbeaver-ui-drawer:11.3.5Aug 01, 2026
openvsxyardensachs/copy-python-path:0.0.1Aug 02, 2026
openvsxmiclo/sort-typescript-imports:0.0.3Aug 02, 2026
openvsxqiu/llvm-ir-language-support:0.0.4Aug 02, 2026
openvsxqiu/llvm-ir-language-support:0.0.6Aug 02, 2026
openvsxjakeboone02/cypher-query-language:0.0.2Aug 02, 2026
openvsxmadhavd1/javadoc-tools:0.0.2Aug 02, 2026
openvsxangelo-breuer/license-header-manager:0.0.2Aug 02, 2026
openvsxwordpresstools/wordpress:0.0.1Aug 02, 2026
openvsxpwrs/cem-language-server-vscode:0.0.1Aug 02, 2026
openvsxjt/jakt:0.0.1Aug 02, 2026
openvsxmkdirdocs/mkd-docs:0.0.1Aug 02, 2026
openvsxydaveluy/xsmp-modeler:0.0.1Aug 02, 2026
openvsxbdaeumer/vscode-eslint:0.0.1Aug 02, 2026
openvsxydaveluy/xsmp-tas-mdk:0.0.1Aug 02, 2026
openvsxnihilus118/perl-debugger:0.0.1Aug 02, 2026
openvsxmagne-sjaastad/opm-flow-editor-support:0.0.1Aug 02, 2026
openvsxdavidpallinder/rails-test-runner:0.0.1Aug 02, 2026
openvsxchris-hock/pioasm:0.0.1Aug 02, 2026
openvsxchavyleung/vscode-pnpm-verlens:0.0.1Aug 02, 2026
openvsxflutterando/flutter-mobx:0.0.1Aug 02, 2026
openvsxgobystrokreactjs/gobystrok:0.0.1Aug 02, 2026
openvsxglavin001/unibeautify-vscode:0.0.1Aug 02, 2026
openvsxhyperledgercomposer/composer-support-client:0.0.1Aug 02, 2026
openvsxinsigne/powershell:0.0.1Aug 02, 2026
openvsxjeremy38100/init-node-script:0.0.1Aug 02, 2026
openvsxlevertion/mcjson:0.0.1Aug 02, 2026
npmapproval-guardian:1.0.7Aug 02, 2026
npmapproval-guardian:1.0.9Aug 02, 2026
npmapproval-guardian:1.1.0Aug 02, 2026
npmsimple-date-formatter-util-1:1.0.0Aug 02, 2026
npmsimple-date-formatter-util-2:1.0.0Aug 02, 2026
npmaccounts-final-form:9.9.12Aug 03, 2026
npmaccounts-loading-state:8.9.6Aug 03, 2026
npmlist-issue-predecessor-dependencies-block:99.0.0Aug 03, 2026
npmfluid-type-ui:2.0.9Aug 03, 2026
npmfluid-type-ui:2.0.8Aug 03, 2026
npm@catamania/front-components:1.0.5Aug 04, 2026
npm@lizhao1/memorax-code-internal:0.1.0Aug 04, 2026
npm@lizhao1/memorax-code-internal:0.1.1Aug 04, 2026
npmsimple-date-formatter-util-4:1.0.0Aug 04, 2026
npmsimple-date-formatter-util-14:1.0.0Aug 04, 2026
npmsimple-date-formatter-util-15:1.0.0Aug 04, 2026
npmsimple-date-formatter-util-16:1.0.0Aug 04, 2026
npmsimple-date-formatter-new-1:1.0.0Aug 04, 2026
npmsimple-date-formatter-new-3:1.0.0Aug 04, 2026
npmsimple-date-formatter-new-5:1.0.0Aug 04, 2026
npmsimple-date-formatter-new-6:1.0.0Aug 04, 2026
npmsimple-date-formatter-new-7:1.0.0Aug 04, 2026
npmsimple-date-formatter-new-8:1.0.0Aug 04, 2026
npm@jsimplify/errno:2.0.7Aug 04, 2026
npm@jsimplify/errno:2.0.6Aug 04, 2026
npm@jsimplify/errno:2.0.8Aug 04, 2026
pypilaunchdarkly-ai-server-sdk:1.9.9Aug 05, 2026
npmemulative:1.0.1Aug 05, 2026
npmpython-bitcoinlib:1.0.0Aug 05, 2026
npmckcc-protocol:1.0.0Aug 05, 2026
npmledger-lib:1.0.0Aug 05, 2026
npmtrezor-lib:1.0.0Aug 05, 2026
npmhwi-lib:1.0.0Aug 05, 2026
npmethers-lib:1.0.0Aug 05, 2026
npmbip32-js:1.0.0Aug 05, 2026
npmethers-lib:1.0.1Aug 05, 2026
npmbip32-js:1.0.1Aug 05, 2026
npmmnemonic-utils:1.0.0Aug 05, 2026
npmckcc-protocol:1.0.1Aug 05, 2026
npmpython-bitcoinlib:1.0.1Aug 05, 2026
npmtrezor-lib:1.0.1Aug 05, 2026
npmledger-lib:1.0.1Aug 05, 2026
npmhwi-lib:1.0.1Aug 05, 2026
npmethereum-sign-utils:1.0.0Aug 05, 2026
npmethers-lib:1.0.2Aug 05, 2026
vscodepi-agent-chat:0.0.1Aug 06, 2026
vscodebin-json:0.0.8Aug 06, 2026
npm@servicetitan/dte-unlayer:0.150.5Aug 06, 2026
npm@servicetitan/dte-unlayer:0.150.4Aug 06, 2026
npm@servicetitan/dte-unlayer:0.150.3Aug 06, 2026
npm@servicetitan/dte-unlayer:0.150.2Aug 06, 2026
npm@servicetitan/dte-unlayer:0.150.1Aug 06, 2026
npmkarapace-docs:1.0.1Aug 06, 2026
npmgithub-app-sts-action:1.0.1Aug 06, 2026
npmfoodi:99.99.1Aug 06, 2026
npmmove-bcs-codec:1.0.0Aug 06, 2026
npmmove-bcs-codec:1.0.1Aug 06, 2026
npmmove-bcs-codec:1.0.2Aug 06, 2026
npmrdfxvela:5.0.1Aug 07, 2026
npmrdfxvela:4.1.0Aug 07, 2026
npmrdfxvela:6.0.0Aug 07, 2026
npmrdfxvela:6.1.0Aug 07, 2026
npmrdfxvela:6.2.1Aug 07, 2026
npmvelabuild:2.0.0Aug 07, 2026
npmvelabuild:1.0.3Aug 07, 2026
npmvelabuild:1.0.2Aug 07, 2026
npmvelabuild:1.0.1Aug 07, 2026
npmvelabuild:1.0.0Aug 07, 2026
npmvelabuild:2.1.0Aug 07, 2026
vscodealanas-is-testing:0.0.1Aug 07, 2026
npmsyft-acp-util:1.0.0Aug 07, 2026
npmsyft-acp-core:1.0.0Aug 07, 2026
npmsyft-acp-uikit:1.0.0Aug 07, 2026
npmsyft-acp-atoms:1.0.0Aug 07, 2026
npmgpt-terminal-cli:1.0.0Aug 07, 2026
npmwormgpt-cli:1.0.0Aug 07, 2026
npmwormgpt-cli:1.0.1Aug 07, 2026
npmwormgpt-cli:1.0.2Aug 07, 2026
npmdojo-rn-interview:1.0.1Aug 07, 2026
npmwormgpt-cli:1.0.3Aug 07, 2026
npmwormgpt-cli:1.0.4Aug 07, 2026
npmwormgpt-cli:1.0.5Aug 07, 2026
npmwormgpt-cli:1.0.7Aug 07, 2026
npmwormgpt-cli:1.0.6Aug 07, 2026
npmwormgpt-cli:1.0.8Aug 07, 2026

When Volume Meets Payload: 206 Malicious Packages This Week

This week’s digest shows two attack patterns running in parallel, not just faster publishing, but publishing built to actually execute. wormgpt-cli went from zero to nine versions on npm in a single day, brazenly named after a real dark-LLM tool sold to cybercriminals, the same automated speed no manual review process can match. A separate cluster of nine packages impersonated cryptocurrency wallet and signing libraries (ledger-lib, trezor-lib, bip32-js, and others), all confirmed within hours of each other on August 5, a synchronized drop timed to win a dependency-confusion race before anyone notices.

But the week’s most serious find wasn’t about volume at all. QuietPolyfill, the beaver-ui-* and accounts-* cluster we broke down in full, turned out to be a three-stage dropper that triggers on require(), not an install script, so --ignore-scripts never sees it. Nineteen of the twenty package names were pulled by their own operator within hours, and one came back the next day under a different account, with the delivery infrastructure still live.

Xygeni Early Malware Warning monitors npm, PyPI, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build, before an AI agent installs them autonomously, and before a dropper like QuietPolyfill gets the chance to execute on the first import. When a package ships nine versions in a day, or a “UI component library” quietly retrieves and runs a signed loader, detection that runs after the fact is already too late.

Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization needed to stay ahead of coordinated supply chain pressure, so your pipelines stay clean without slowing your teams down.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
Get your Free Account.
No credit card required.

Secure your Software Development and Delivery

with Xygeni Product Suite