Malicious Code Digest 85

Xygeni Malicious Code Digest 85

Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 53 malicious packages between August 21 and August 28, 2026, led by a continuation of the Baileys impersonation campaign flagged last week, a cluster of seven identically-versioned e-commerce-branded packages published in a single day, and a wave of authentication-themed packages (TOTP, 2FA, OTP) spread across five separate naming variants.

The Baileys impersonation continued under @vanzxy/baileys, with seven new versions (1.4.3 through 1.4.9) confirmed between August 22 and 23, the same rapid-iteration pattern seen the week prior.

A cluster of seven packages (sm-billing-form, sm-cart, sm-payment, sm-checkout, sm-session, sm-admin, sm-apikey-model) were all published at the identical version 99.0.1 on August 24, an unusual shared version number across supposedly independent, e-commerce-themed package names.

Also worth flagging: a spread of authentication-related package names, totp-utils, secret-key-totp, secretkey-2fa, secretkey2fa, and 2fa-secretkey, appeared across the week under different naming conventions but a shared theme, alongside auth-otp, which published five versions in a single day (August 24).

This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats to help DevSecOps teams protect their pipelines before damage occurs.

Ecosystem Package Date
npmtotp-utils:1.4.3August 21, 2026
npmtotp-utils:1.4.4August 21, 2026
npm@vanzxy/baileys:1.4.3August 22, 2026
npm@vanzxy/baileys:1.4.4August 22, 2026
npmtotp-utils:1.4.5August 23, 2026
npmtotp-utils:1.4.8August 23, 2026
npmtotp-utils:1.4.7August 23, 2026
npmtotp-utils:1.4.6August 23, 2026
npmtotp-utils:1.4.9August 23, 2026
npm@vanzxy/baileys:1.4.5August 23, 2026
pypikisama:0.4.6August 23, 2026
npm@vanzxy/baileys:1.4.6August 23, 2026
npm@vanzxy/baileys:1.4.7August 23, 2026
npm@vanzxy/baileys:1.4.8August 23, 2026
npm@vanzxy/baileys:1.4.9August 23, 2026
pypimlflow-otel-instrumentor:1.1.0August 23, 2026
npmsecret-key-totp:1.5.1August 23, 2026
pypienvprovision:1.4.0August 23, 2026
pypienvprovision:1.3.0August 23, 2026
npmsm-billing-form:99.0.1August 24, 2026
npmsm-cart:99.0.1August 24, 2026
npmsm-payment:99.0.1August 24, 2026
npmsm-checkout:99.0.1August 24, 2026
npmsm-session:99.0.1August 24, 2026
npmsm-admin:99.0.1August 24, 2026
npmsm-apikey-model:99.0.1August 24, 2026
npmdotish:1.0.0August 24, 2026
npmopenai-pr-reviewer:1.0.0August 24, 2026
npmremove-bg-serverless-azure:1.0.1August 24, 2026
npmauth-otp:1.0.3August 24, 2026
npmauth-otp:1.0.2August 24, 2026
npmauth-otp:1.0.1August 24, 2026
npmauth-otp:1.0.4August 24, 2026
npmauth-otp:1.0.5August 24, 2026
npmsecretkey-2fa:1.0.1August 24, 2026
pypiminecraft-ytreceiver:0.1.0August 25, 2026
pypiminecraft-ytreceiver:0.2.0August 25, 2026
pypiminecraft-ytreceiver:0.4.0August 25, 2026
pypiminecraft-ytreceiver:0.3.0August 25, 2026
pypiminecraft-ytreceiver:0.5.0August 25, 2026
npmmoidevz:1.0.0August 26, 2026
npmcloud-baileys:1.1.36August 26, 2026
npmzenntechinc-cli:1.6.6August 26, 2026
npmzenntechinc-cli:1.6.4August 26, 2026
npmmt-ts-serverless-starter:1.0.1August 26, 2026
npmoctopus-action:1.0.1August 26, 2026
npmsecretkey2fa:1.0.1August 26, 2026
npmmoideva:1.0.0August 27, 2026
npmvs-modules:1.2.2August 27, 2026
npmrn-push-provisioning:99.0.1August 27, 2026
npm2fa-secretkey:1.0.5August 28, 2026
npm2fa-secretkey:1.0.6August 28, 2026
npm2fa-secretkey:1.0.7August 28, 2026

Same Version, Seven Names: 53 Malicious Packages This Week

This week’s digest shows the same pressure from two different angles: a campaign still iterating on an old alias, and a fresh cluster hiding behind a shared, unusual detail.

The Baileys impersonation campaign flagged last week hasn’t stopped. @vanzxy/baileys published seven new versions (1.4.3 through 1.4.9) between August 22 and 23, the same climbing-version pattern seen the week before under a different alias, consistent with an attacker adjusting the package name rather than abandoning the attempt after detection.

A separate cluster gave itself away through version numbers rather than names. Seven e-commerce-branded packages (sm-billing-form, sm-cart, sm-payment, sm-checkout, sm-session, sm-admin, sm-apikey-model) all shipped under the identical version 99.0.1 on August 24, an unusual coincidence across supposedly independent projects that points to one actor behind all seven. A separate wave of authentication-themed packages, totp-utils, secret-key-totp, secretkey-2fa, secretkey2fa, and 2fa-secretkey, spread the same theme across five different naming conventions over the week, with auth-otp alone publishing five versions in a single day.

Xygeni Early Malware Warning monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When seven unrelated-looking package names publish under the same version number on the same day, or a campaign resurfaces under a new alias a week after the last one, detection that only checks once is already behind.

Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization needed to stay ahead of coordinated supply chain pressure, so your pipelines stay clean without slowing your teams down.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
Get your Free Account.
No credit card required.

Secure your Software Development and Delivery

with Xygeni Product Suite