Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 114 malicious packages between August 7 and August 14, 2026, led by an npm package cluster openly branded after a real dark-LLM attacker tool, a dependency-confusion wave targeting DeFi and Web3 protocol libraries, and a large-scale brand-squatting campaign against a Brazilian fintech provider.
The most attention-grabbing find: wormgpt-cli on npm, nine versions published in rapid succession on August 7, alongside a companion package, gpt-terminal-cli, published the same day. The name is a direct reference to WormGPT, a real dark-LLM tool marketed to cybercriminals for phishing and malware generation, suggesting the package is trading on the brand recognition of an actual attacker tool rather than hiding behind a neutral name.
A separate cluster targeted decentralized finance infrastructure directly: ten package names on npm impersonating real DeFi protocol and standards libraries (ethereum-vault-connector, boring-vault, camelot-ammv2-core, camelot-ammv2-periphery, @aerodrome-finance/contracts, @aerodrome-finance/slipstream, permit2, @openzeppelin-4/contracts, @openzeppelin-5/contracts, passkeys-react), sixteen confirmed versions in total, published within hours of each other on August 11. It’s a dependency-confusion play aimed squarely at developers building on Camelot, Aerodrome Finance, and OpenZeppelin’s standard contracts.
The largest single cluster this week impersonated Alelo, a Brazilian corporate benefits and payment card provider: ten distinct package names (alelo-core, alelo-api, alelo-client, alelo-utils, alelo-auth, alelo-sdk, alelo-services, alelo-common, alelo-payment, meualelo), most published in two or three versions, for twenty-one confirmed packages on August 14 alone. Alongside it, a separate scoped-namespace campaign published twenty-one lookalike n8n-nodes-utils-helper-* packages across three npm scopes (@years17, @years18, @years20) between August 13 and 14, a pattern consistent with automated squatting against the n8n automation platform’s node ecosystem rather than a single hand-crafted attack.
Two Maven packages published under io.github.davidtimur/c2-lab on August 7 are worth flagging on name alone. C2 is short for command-and-control, and a package advertising that function in its own name is either remarkably careless or testing how fast detection catches up. For more on Maven-specific supply chain risk, see our analysis of JavaCDoor, a compile-time backdoor we uncovered in the Maven ecosystem.
This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats and provide actionable intelligence to help DevSecOps teams protect their pipelines before damage occurs.
When a Name Gives It Away: 114 Malicious Packages This Week
This week’s digest shows attackers leaning on brand recognition rather than hiding from it. wormgpt-cli went from zero to nine versions on npm in a single day, brazenly named after a real dark-LLM tool sold to cybercriminals, alongside a companion package, gpt-terminal-cli, published the same day. Two Maven packages went further still, publishing openly under the name c2-lab, command-and-control spelled out in the package name itself.
Volume told its own story elsewhere. A ten-package cluster impersonating DeFi protocol libraries (ethereum-vault-connector, boring-vault, camelot-ammv2-core, and others) landed sixteen confirmed versions within hours of each other on August 11, a synchronized drop aimed at developers pulling in what look like standard contracts from Camelot, Aerodrome Finance, and OpenZeppelin. Days later, a ten-name cluster impersonating Alelo, a Brazilian corporate benefits provider, produced twenty-one confirmed packages in a single day, while a parallel campaign squatted twenty-one lookalike n8n-nodes-utils-helper-* names across three separate npm scopes, a pattern that points to automated squatting infrastructure rather than one attacker working by hand.
Xygeni Early Malware Warning monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When a scoped namespace produces twenty-one lookalike packages in two days, or a Maven artifact ships with its intent in the name, detection that runs after the fact is already too late.
Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization needed to stay ahead of coordinated supply chain pressure, so your pipelines stay clean without slowing your teams down.





