xygeni malicious code digest 89

Xygeni Malicious Code Digest 89

As every week, our malware detection systems scan thousands of new and updated packages across public registries. We confirmed 24 malicious package versions between September 18 and 25, 2026, all of them on npm, with six sequentially numbered packages published in the same two minutes, a scoped namespace attacked from three directions at once, and a pair of names that point straight at an internal package.

simple-date-formatter-new-11 through -16 were published on September 25 between 06:01 and 06:03, six packages at version 1.0.0, distinguishable only by the number on the end. The naming is the tell. Nobody iterating on a date formatter arrives at version eleven through sixteen in under two minutes. It is a sequence generated to occupy names, and the plain-utility framing is what makes it survive a glance in a dependency list.

siriusbeyond appeared in two forms on the same operation: as an unscoped package at 1.0.0 on September 20, then as @siriusbeyond/auth, @siriusbeyond/ui and @siriusbeyond/utils, all pinned at 99.0.0, on September 24, alongside @dbbhk/ui-components at the same version and in the same batch. Covering the scoped and unscoped forms of a name is a bet on how the target’s resolver behaves rather than on which package a developer reaches for.

Also worth noting: commerce-materials and byted-commerce-materials were published one minute apart, both at 1.0.0, and the pairing of a generic name with a vendor-prefixed twin is the shape dependency confusion takes when the attacker knows the internal package exists. Version inflation ran through the week again in bulk-add-sdk at 1.99.99, @alphaspace/core at 99.0.1 and 99.0.2, and the 99.0.0 cluster above. n8n-nodes-data-transformer-utils continues the run of n8n node impersonation we flagged last week, and my-auto-follow shipped 1.0.6 and 1.0.7 back to back.

This weekly snapshot is part of our ongoing Malicious Code Digest, where we validate new threats to help DevSecOps teams protect their pipelines before damage occurs.

EcosystemPackageDate
npmtest890-auth:1.0.0September 18, 2026
npmbulk-add-sdk:1.99.99September 19, 2026
npmcloud-baileys:1.1.41September 19, 2026
npmbyted-commerce-materials:1.0.0September 20, 2026
npmcommerce-materials:1.0.0September 20, 2026
npmmy-auto-follow:1.0.6September 20, 2026
npmmy-auto-follow:1.0.7September 20, 2026
npmsiriusbeyond:1.0.0September 20, 2026
npmsysverify:2.0.10September 22, 2026
npmsysverify:2.0.9September 22, 2026
npmn8n-nodes-data-transformer-utils:1.0.0September 23, 2026
npmtake-home-caller-id:1.0.1September 23, 2026
npm@dbbhk/ui-components:99.0.0September 24, 2026
npm@siriusbeyond/auth:99.0.0September 24, 2026
npm@siriusbeyond/ui:99.0.0September 24, 2026
npm@siriusbeyond/utils:99.0.0September 24, 2026
npm@alphaspace/core:99.0.1September 25, 2026
npm@alphaspace/core:99.0.2September 25, 2026
npmsimple-date-formatter-new-11:1.0.0September 25, 2026
npmsimple-date-formatter-new-12:1.0.0September 25, 2026
npmsimple-date-formatter-new-13:1.0.0September 25, 2026
npmsimple-date-formatter-new-14:1.0.0September 25, 2026
npmsimple-date-formatter-new-15:1.0.0September 25, 2026
npmsimple-date-formatter-new-16:1.0.0September 25, 2026

Six in Two Minutes: 24 Malicious Package Versions This Week

This week’s digest is smaller than the last one and tighter in shape: 24 confirmed versions, every one of them on npm, with six sequentially numbered packages published inside the same two minutes and a single name attacked in scoped and unscoped form at once.

simple-date-formatter-new-11 through -16 went up on September 25 between 06:01 and 06:03, all at 1.0.0, identical but for the digit on the end. Nobody reaches version sixteen of a date formatter in two minutes. That is name occupation, dressed in the most boring utility label available so it survives a glance in a dependency list. The siriusbeyond operation went the other way, covering both forms of the same name: an unscoped package on September 20, then @siriusbeyond/auth, /ui and /utils at 99.0.0 four days later, with @dbbhk/ui-components in the same batch. Betting on both forms is a bet on the resolver rather than on the developer.

And the pairing worth watching closest: commerce-materials and byted-commerce-materials, published a minute apart at the same version. A generic name beside a vendor-prefixed twin is what dependency confusion looks like when the attacker already knows the internal package exists. Version inflation ran underneath all of it again, in bulk-add-sdk at 1.99.99 and @alphaspace/core at 99.0.1 and 99.0.2.

None of these names had a signature when they landed. They were new, which is the entire point.

Xygeni Malware Early Warning monitors npm, PyPI, Maven, Composer, OpenVSX and other registries in real time, flagging threats at publication, before they reach a build and before an AI agent installs them autonomously. When six packages appear in two minutes, detection that waits for a signature is not late by days, it is late by the whole attack.

Xygeni’s Open Source Security platform gives DevSecOps teams the real-time detection and prioritization to stay ahead of coordinated supply chain pressure.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
Get your Free Account.
No credit card required.

Secure your software development and delivery

with Xygeni Product Suite