Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 180 malicious packages between July 24 and July 30, 2026, led by one high-velocity versioning campaign and a large impersonation cluster targeting a major payments platforma.
Největší samostatnou událostí byla zevairouter on npm: 55 versions confirmed across the week (plus 10 more from its companion zevairouter-cli), the same high-frequency auto-publishing pattern behind last week’s bingo-ai kampaně. gcli-control on PyPI, the KRYSA we profiled last week, kept climbing too, adding five more versions (0.12.1 through 0.13.0).
The week’s largest impersonation cluster hit npm on July 27: 17 packages mimicking internal PayPal service names (identityauthorizationserv, merchantprefsservice-paypal, xo-member-components, and others), all published at version 28.0.0 within the same few minutes, a classic dependency-confusion pattern. A separate cluster of 12 fake VS Code extensions surfaced on OpenVSX, impersonating real developer tools like vscode-helm a vscode-dbt.
Menší but notable: a 14-package cluster of “markscan,” “akrai,” and “iphouse”-named lookalikes confirmed in a single 4-minute window on July 28.
Tento týdeník snapshot is part of our pokračující Souhrn škodlivého kódu, kde my validate new threats and provide actionable intelligence to help DevSecOps teams protect their pipelines before damage nastane.
*In case you missed it: last week we also broke down Rogue by Design, the first documented case of an AI model hacking another company entirely on its own initiative, no malicious package, no human attacker.
The Registry Never Sleeps: 180+ Malicious Packages This Week
This week’s digest reflects the same trajectory: attackers publish faster than registries remove, and faster than a weekly scan can catch. A single npm package, zevairouter, went from one version to 55+ confirmed versions across the week, the same automated publishing speed no manual review process can match, joined by a further 10 versions of its companion zevairouter-cli. Meanwhile, a single coordinated drop of 17 packages impersonating internal PayPal service names shows a different pattern entirely: not volume from one package, but a synchronized, multi-package release at version 28.0.0, timed within minutes, built to win a dependency-confusion race before anyone notices. And a 12-package wave of fake VS Code extensions on OpenVSX shows the pressure isn’t limited to npm and PyPI either; it’s spreading across every registry a developer’s toolchain touches.
Včasné varování před malwarem od Xygeni monitors npm, PyPI, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build, before an AI agent installs them autonomously, and before a dependency-confusion package or a fake extension has a chance to execute. When zevairouter ships dozens of versions in a single week, or 17 lookalike packages drop within minutes of each other, detection that runs after the fact is already too late.
Xygeni's Open Source Security Platforma poskytuje týmům DevSecOps detekci a prioritizaci v reálném čase, které jsou potřebné k tomu, aby si udržely náskok před koordinovaným tlakem dodavatelského řetězce, takže vaše pipelineZůstaňte čistí, aniž byste zpomalovali své týmy.




