Schadcode-Digest Juni

Monatliche Zusammenfassung des Malicious Code Digest: Juli

Welcome to the July edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed over 780 malicious packages across npm, PyPI, and OpenVSX (the VS Code extension marketplace), tracked across five weekly digests.

July was defined by three converging trends: sustained, high-volume version-flooding campaigns designed to outlast takedowns; a sharp escalation in attacks targeting AI tooling, MCP servers, and agentic workflows; and coordinated dependency-confusion campaigns against both enterprise namespaces and crypto/DeFi ecosystems.

Zu den bemerkenswertesten Kampagnen, die in diesem Monat dokumentiert wurden:

  • bingo-ai on PyPI resurfaced twice, flooding the registry with well over 150 versions across two bursts (July 13 and July 21), confirming this is an ongoing operation, not a one-off.
  • zevairouter became July’s largest single-package campaign: over 65 versions across npm, published continuously from July 25–28.
  • gcli-control, the Windows RAT we profiled in detail that routes its C2 through npoint.io, escalated from version 0.1.0 to 0.13.0 across three separate weeks.
  • @szc-ft/mcp-szcd-client, the package behind SkillLeak, our writeup on a credential decryptor delivered through a bundled MCP skill, was confirmed July 2.
  • The week of July 7 brought the month’s heaviest AI-tooling targeting: mcp-server-pg, anthropic-toolkit, openai-agents-helpers, ollama-helpers und @langgraphjs/toolkit, impersonating MCP, Anthropic, OpenAI, Ollama, and LangGraph.
  • A 17-package PayPal impersonation cluster hit npm July 27, all at version 28.0.0 within minutes.
  • @wagni_bot, roughly 60 npm packages impersonating crypto wallet SDKs (Ethereum, Solana, Binance, and more), all published in a single day, July 10.
  • Over a dozen fake VS Code extensions surfaced on OpenVSX, confirming attackers are expanding beyond package registries into the IDE itself.

The defining pattern of July: attacks increasingly target the AI agents and automated tooling that install packages with no human reviewer in the loop, at a publishing velocity built to outrun manual review.

Below is a summary of what we found. You can see all five weeks’ data disclosed in full detail at the Malicious Code Digest index.

Woche 5: Über 180 Pakete entdeckt

Ökosystem Verpackung Bestätigt
npm@cryptosrvc/shift-sdk-v4:1.0.7724. Juli 2026
OpenVSXcesium/gltf-vscode:0.0.124. Juli 2026
Abonnierengcli-control:0.13.024. Juli 2026
vscodeairtune:1.0.025. Juli 2026
npmzevairouter:1.0.10925. Juli 2026
npmidentityauthorizationserv:28.0.027. Juli 2026
npmmerchantprefsservice-paypal:28.0.027. Juli 2026
npmxo-member-components:28.0.027. Juli 2026
OpenVSXtechnosophos/vscode-helm:0.0.127. Juli 2026
OpenVSXbastienboutonnet/vscode-dbt:0.0.127. Juli 2026
npmmarkscan:1.0.028. Juli 2026
npmiphouse:1.0.028. Juli 2026
npmakrai-report-new:1.0.028. Juli 2026
Abonnierenvtranalytic:8.0.028. Juli 2026
npmgreatcall-customers-commandapi:99.0.029. Juli 2026
npmblots:2.1.129. Juli 2026
npm@ey-china/ey-assistant:1.0.130. Juli 2026
npmflydev:0.0.130. Juli 2026
npm@qtestorgz/sdk:1.0.030. Juli 2026

Woche 4: Über 165 Pakete entdeckt

Ökosystem Verpackung Bestätigt
npmjavas-crypto:2.0.417. Juli 2026
npmclover-codelab-remote-pay-cloud:99.9.917. Juli 2026
npmaftermath-finance:99.0.019. Juli 2026
npmtwilio-serverless:99.99.9921. Juli 2026
npmsupplyhub:1.0.121. Juli 2026
npm@offa/offa-uwk:999.0.021. Juli 2026
npmdate-format-utils-xz:1.0.121. Juli 2026
Abonnierenbingo-ai:6.2.24121. Juli 2026
npm@bpa-internal/bpa-utils:99.99.9922. Juli 2026
npmn8n-nodes-pwn:1.0.122. Juli 2026
Abonnierengcli-control:0.1.022. Juli 2026
npmuniswap-sdk-v4:1.0.023. Juli 2026
npmwagmi-react:1.0.023. Juli 2026
npmethers-secure:1.0.023. Juli 2026
Abonnierengcli-control:0.12.024. Juli 2026
npmdatefmt-pro:1.0.124. Juli 2026
npm@daylightqc/date-fmt-lite:1.0.024. Juli 2026

Woche 3: Über 145 Pakete entdeckt

Ökosystem Verpackung Bestätigt
npmenv-fast:1.0.011. Juli 2026
Abonnierenmoon-uv:0.0.2512. Juli 2026
npmgoogle-caja-bower:1000.800.2013. Juli 2026
npmvuln-package:99.9.1413. Juli 2026
Abonnierenbingo-ai:6.2.10913. Juli 2026
npmbugexploit:99.9.913. Juli 2026
npmamdocs-core-package:11.11.1114. Juli 2026
npmarb-kit:1.0.014. Juli 2026
npmsolana-key-utils:1.0.014. Juli 2026
npmaxios-test-one:1.18.915. Juli 2026
AbonnierenPlungerhacker:2.0.115. Juli 2026
Abonnierenlog-guru:0.7.816. Juli 2026
Abonnierenpylogora:0.7.816. Juli 2026
npm@across-toolkit/eslint-config:99.0.017. Juli 2026
npmvalidpilot-mcp:1.4.017. Juli 2026
npmnyxora:26.7.1717. Juli 2026

Woche 2: Über 200 Pakete entdeckt

Ökosystem Verpackung Bestätigt
Abonnierenprocwire:5.2.74. Juli 2026
npmNeon-Terminal:0.3.04. Juli 2026
npmnolimit-agent:1.0.3366. Juli 2026
vscodeandroid-support-framework-vs:0.0.16. Juli 2026
npmmcp-server-pg:1.0.07. Juli 2026
npmanthropic-toolkit:1.3.17. Juli 2026
npmopenai-agents-helpers:1.3.37. Juli 2026
npmdebugcli:4.4.17. Juli 2026
npmhello244a:1.0.387. Juli 2026
npmthunder-rony:99.9.98. Juli 2026
Abonnierenmoon-uv:0.0.59. Juli 2026
npmes6-codify:2.0.09. Juli 2026
npmn8n-nodes-mcputils:0.1.49. Juli 2026
npm@wagni_bot/hyperliquid-sdk:1.0.010. Juli 2026
npm@wagni_bot/metemask-sdk:1.0.010. Juli 2026
npm@wagni_bot/pumpfun-sdk:1.0.010. Juli 2026
npm@wagni_bot/binance-sdk:1.0.010. Juli 2026
npm@wagni_bot/ethereum-wallet:1.0.010. Juli 2026
npmtesting-d3do:99.9.910. Juli 2026
npmclient-cookies-agent:99.9.610. Juli 2026

Woche 1: Über 90 Pakete entdeckt

Ökosystem Verpackung Bestätigt
npmcursed-modules:999.1.21. Juli 2026
npm@szc-ft/mcp-szcd-client:0.39.02. Juli 2026
npmpp-react-v5:30.0.21. Juli 2026
npmconstellai:0.5.11. Juli 2026
npmdate-fns-lite:1.0.92. Juli 2026
npm@easypayment/medusa-paypal:0.7.62. Juli 2026
npmdl-pp-latm:80.4.22. Juli 2026
npm@sudoughnym/enviro-demo:99.99.991. Juli 2026
npmnolimit-agent:1.0.3162. Juli 2026
npmcursed-ecto-d3ab00:1.0.03. Juli 2026
npm@checkrhq/adjudication-api-client:0.0.23. Juli 2026

From Version Storms to AI Impersonation: What July’s Supply Chain Attacks Reveal

The campaigns above aren’t edge cases, they’re the baseline now. Version-flooding storms, coordinated impersonation drops, and AI-tooling lookalikes are hitting real teams in real SDLCs every week, often with no human in the loop between publication and install.

Xygenis Malware-Erkennung und supply chain security platform gives organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. Coverage spans npm, PyPI, OpenVSX, and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.

Jeder Befund wird automatisch nach Ausnutzbarkeit, Erreichbarkeit und geschäftlichen Auswirkungen priorisiert, sodass sich Ihr Team auf das konzentriert, was tatsächlich behoben werden muss, und nicht auf irrelevante Informationen.

Erkunden Sie jedes vom Xygeni-Sicherheitsteam validierte Schadpaket und jede Kampagne in der Übersicht über bösartigen Code.

Bleiben Sie sicher. Bleiben Sie schnell. Behalten Sie die Kontrolle mit Xygeni.

SCA-Tools-Software-Zusammensetzungs-Analyse-Tools
Priorisieren, beheben und sichern Sie Ihre Softwarerisiken
Sichern Sie sich Ihr kostenloses Konto.
Keine Kreditkarte erforderlich.

Sichern Sie Ihre Softwareentwicklung und -bereitstellung

mit der Xygeni-Produktsuite