malicious code digest 84

Xygeni Malicious Code Digest 84

Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 34 malicious packages between August 15 and August 20, 2026, led by a sustained impersonation campaign against Baileys, a popular open-source WhatsApp Web API library, a cluster of Twilio/HackerOne-branded probe packages, and a set of unrelated-looking npm packages sharing an identical, unusually high version number.

The Baileys impersonation ran the longest: four separate package names (@mrlegendbot/baileys, cloud-baileys, @vanzxy/baileys, ourin-baileys) confirmed across six days, with cloud-baileys alone republished four times between August 15 and 20 under climbing version numbers, a pattern consistent with an attacker iterating past detection rather than a one-off upload.

A separate cluster on August 15 published packages referencing Twilio and HackerOne (twilio-hackerone-poc-afe6937c, five versions in one day, plus tw-pkgprobe-7731 and hunterone-build-probe-9210), naming conventions typically associated with bug-bounty or dependency-confusion probing rather than a disguised payload.

Also worth flagging: pump-segments-sdk, carbon-monorepo, and pump-fun-skills, three otherwise unrelated package names all published at version 20.1.1 on August 19, an unusual shared version number across supposedly independent projects that suggests a single actor behind all three.

This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats to help DevSecOps teams protect their pipelines before damage occurs.

Ecosystem Package Date
npmhunterone-build-probe-9210:1.0.0August 15, 2026
npmtwilio-hackerone-poc-afe6937c:1.0.0August 15, 2026
npmtw-pkgprobe-7731:1.0.0August 15, 2026
npmtwilio-hackerone-poc-afe6937c:1.0.1August 15, 2026
npmtwilio-hackerone-poc-afe6937c:1.0.2August 15, 2026
npmtwilio-hackerone-poc-afe6937c:1.0.3August 15, 2026
npmtwilio-hackerone-poc-afe6937c:1.0.4August 15, 2026
npm@mrlegendbot/baileys:1.2.4August 15, 2026
npmcloud-baileys:1.1.3August 15, 2026
npm@vanzxy/baileys:1.4.2August 16, 2026
npmourin-baileys:9.0.11August 16, 2026
npmeyiouss:4.0.1August 16, 2026
npmcloud-baileys:1.1.33August 16, 2026
npmmoidev:1.0.0August 16, 2026
npm@wangjiezhong/dsh-memory:0.1.1August 17, 2026
npm@wangjiezhong/dsh-memory:0.1.2August 17, 2026
npm@wangjiezhong/dsh-memory:0.1.3August 17, 2026
npm@wangjiezhong/dsh-memory:0.1.4August 17, 2026
npmmoidevx:1.0.0August 17, 2026
npmdxr-dos:0.1.2August 17, 2026
npmdxr-dos:0.1.1August 17, 2026
npmdxr-dos:0.1.3August 17, 2026
npmcloud-baileys:1.1.34August 18, 2026
pypireqcrypt:0.1.0August 18, 2026
npmdxrs-dos:0.1.3August 18, 2026
npmprism-registry:1.0.1August 18, 2026
npmoptimizely-starter-kit-for-fastly-compute:1.0.1August 18, 2026
npm@mohamed_nowisar/canary-confirm-token3:0.0.1August 18, 2026
npm@mohamed_nowisar/depconf-canary-test:0.0.1August 18, 2026
npm@mohamed_nowisar/token3-check:0.0.1August 18, 2026
npmpump-segments-sdk:20.1.1August 19, 2026
npmcarbon-monorepo:20.1.1August 19, 2026
npmpump-fun-skills:20.1.1August 19, 2026
npmcloud-baileys:1.1.35August 20, 2026

When Iteration Beats Detection: 34 Malicious Packages This Week

This week’s digest shows attackers leaning on persistence rather than a single lucky upload. The cloud-baileys impersonation of the popular WhatsApp Web API library was republished four separate times between August 15 and 20 under climbing version numbers, joined by three other lookalike names (@mrlegendbot/baileys, @vanzxy/baileys, ourin-baileys), a sustained campaign rather than a one-off attempt.

Naming conventions gave other clusters away just as fast. A group of packages branded around Twilio and HackerOne, including twilio-hackerone-poc-afe6937c published in five versions in a single day, alongside tw-pkgprobe-7731 and hunterone-build-probe-9210, used naming patterns typically associated with bug-bounty or dependency-confusion probing. Elsewhere, three unrelated package names (pump-segments-sdk, carbon-monorepo, pump-fun-skills) all shipped under the identical version number 20.1.1 on the same day, an unusual coincidence that points to one actor operating behind all three.

Xygeni Early Malware Warning monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When the same package name resurfaces four times in six days under a new version each time, detection that only checks once is already behind.

Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization needed to stay ahead of coordinated supply chain pressure, so your pipelines stay clean without slowing your teams down.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
Get your Free Account.
No credit card required.

Secure your Software Development and Delivery

with Xygeni Product Suite