Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 53 malicious packages between August 21 and August 28, 2026, led by a continuation of the Baileys impersonation campaign flagged last week, a cluster of seven identically-versioned e-commerce-branded packages published in a single day, and a wave of authentication-themed packages (TOTP, 2FA, OTP) spread across five separate naming variants.
The Baileys impersonation continued under @vanzxy/baileys, with seven new versions (1.4.3 through 1.4.9) confirmed between August 22 and 23, the same rapid-iteration pattern seen the week prior.
A cluster of seven packages (sm-billing-form, sm-cart, sm-payment, sm-checkout, sm-session, sm-admin, sm-apikey-model) were all published at the identical version 99.0.1 on August 24, an unusual shared version number across supposedly independent, e-commerce-themed package names.
Also worth flagging: a spread of authentication-related package names, totp-utils, secret-key-totp, secretkey-2fa, secretkey2fa, and 2fa-secretkey, appeared across the week under different naming conventions but a shared theme, alongside auth-otp, which published five versions in a single day (August 24).
This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats to help DevSecOps teams protect their pipelines before damage occurs.
| Ecosystem | Package | Date |
|---|---|---|
| npm | totp-utils:1.4.3 | August 21, 2026 |
| npm | totp-utils:1.4.4 | August 21, 2026 |
| npm | @vanzxy/baileys:1.4.3 | August 22, 2026 |
| npm | @vanzxy/baileys:1.4.4 | August 22, 2026 |
| npm | totp-utils:1.4.5 | August 23, 2026 |
| npm | totp-utils:1.4.8 | August 23, 2026 |
| npm | totp-utils:1.4.7 | August 23, 2026 |
| npm | totp-utils:1.4.6 | August 23, 2026 |
| npm | totp-utils:1.4.9 | August 23, 2026 |
| npm | @vanzxy/baileys:1.4.5 | August 23, 2026 |
| pypi | kisama:0.4.6 | August 23, 2026 |
| npm | @vanzxy/baileys:1.4.6 | August 23, 2026 |
| npm | @vanzxy/baileys:1.4.7 | August 23, 2026 |
| npm | @vanzxy/baileys:1.4.8 | August 23, 2026 |
| npm | @vanzxy/baileys:1.4.9 | August 23, 2026 |
| pypi | mlflow-otel-instrumentor:1.1.0 | August 23, 2026 |
| npm | secret-key-totp:1.5.1 | August 23, 2026 |
| pypi | envprovision:1.4.0 | August 23, 2026 |
| pypi | envprovision:1.3.0 | August 23, 2026 |
| npm | sm-billing-form:99.0.1 | August 24, 2026 |
| npm | sm-cart:99.0.1 | August 24, 2026 |
| npm | sm-payment:99.0.1 | August 24, 2026 |
| npm | sm-checkout:99.0.1 | August 24, 2026 |
| npm | sm-session:99.0.1 | August 24, 2026 |
| npm | sm-admin:99.0.1 | August 24, 2026 |
| npm | sm-apikey-model:99.0.1 | August 24, 2026 |
| npm | dotish:1.0.0 | August 24, 2026 |
| npm | openai-pr-reviewer:1.0.0 | August 24, 2026 |
| npm | remove-bg-serverless-azure:1.0.1 | August 24, 2026 |
| npm | auth-otp:1.0.3 | August 24, 2026 |
| npm | auth-otp:1.0.2 | August 24, 2026 |
| npm | auth-otp:1.0.1 | August 24, 2026 |
| npm | auth-otp:1.0.4 | August 24, 2026 |
| npm | auth-otp:1.0.5 | August 24, 2026 |
| npm | secretkey-2fa:1.0.1 | August 24, 2026 |
| pypi | minecraft-ytreceiver:0.1.0 | August 25, 2026 |
| pypi | minecraft-ytreceiver:0.2.0 | August 25, 2026 |
| pypi | minecraft-ytreceiver:0.4.0 | August 25, 2026 |
| pypi | minecraft-ytreceiver:0.3.0 | August 25, 2026 |
| pypi | minecraft-ytreceiver:0.5.0 | August 25, 2026 |
| npm | moidevz:1.0.0 | August 26, 2026 |
| npm | cloud-baileys:1.1.36 | August 26, 2026 |
| npm | zenntechinc-cli:1.6.6 | August 26, 2026 |
| npm | zenntechinc-cli:1.6.4 | August 26, 2026 |
| npm | mt-ts-serverless-starter:1.0.1 | August 26, 2026 |
| npm | octopus-action:1.0.1 | August 26, 2026 |
| npm | secretkey2fa:1.0.1 | August 26, 2026 |
| npm | moideva:1.0.0 | August 27, 2026 |
| npm | vs-modules:1.2.2 | August 27, 2026 |
| npm | rn-push-provisioning:99.0.1 | August 27, 2026 |
| npm | 2fa-secretkey:1.0.5 | August 28, 2026 |
| npm | 2fa-secretkey:1.0.6 | August 28, 2026 |
| npm | 2fa-secretkey:1.0.7 | August 28, 2026 |
Same Version, Seven Names: 53 Malicious Packages This Week
This week’s digest shows the same pressure from two different angles: a campaign still iterating on an old alias, and a fresh cluster hiding behind a shared, unusual detail.
The Baileys impersonation campaign flagged last week hasn’t stopped. @vanzxy/baileys published seven new versions (1.4.3 through 1.4.9) between August 22 and 23, the same climbing-version pattern seen the week before under a different alias, consistent with an attacker adjusting the package name rather than abandoning the attempt after detection.
A separate cluster gave itself away through version numbers rather than names. Seven e-commerce-branded packages (sm-billing-form, sm-cart, sm-payment, sm-checkout, sm-session, sm-admin, sm-apikey-model) all shipped under the identical version 99.0.1 on August 24, an unusual coincidence across supposedly independent projects that points to one actor behind all seven. A separate wave of authentication-themed packages, totp-utils, secret-key-totp, secretkey-2fa, secretkey2fa, and 2fa-secretkey, spread the same theme across five different naming conventions over the week, with auth-otp alone publishing five versions in a single day.
Xygeni Early Malware Warning monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When seven unrelated-looking package names publish under the same version number on the same day, or a campaign resurfaces under a new alias a week after the last one, detection that only checks once is already behind.
Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization needed to stay ahead of coordinated supply chain pressure, so your pipelines stay clean without slowing your teams down.





