Malicious Code Digest September Recap

Resumen mensual de Malicious Code Digest: septiembre

Welcome to the September edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed 104 malicious packages across npm and PyPI, tracked across four weekly digests.

September was defined by three converging trends: campaigns that carried straight over from August and kept going despite takedowns; dependency confusion at scale, with dozens of packages claiming inflated version numbers like 99.0.0 y 19999.x to hijack private namespaces; and a clear move toward the plugin and automation ecosystems developers trust with privileged access, such as Strapi, n8n and MCP.

Entre las campañas más destacadas documentadas este mes:

  • El self-deleting anti-proctoring operator returned on September 1, with amicat, bmcat, eyevox y moidevh confirmed alongside two new names from the same stem, moidevk y moidevl.
  • Baileys, the WhatsApp Web API library impersonated throughout August, stayed under attack: cloud-baileys reached versions 1.1.37 y 1.1.38 in the first week and 1.1.41 by September 19, making it one of the longest-running impersonations we have tracked.
  • A 21-package campaign (September 15 to 17) published fake Strapi plugins under the “meeb” tag, all at the identical version 3.6.8, alongside companion packages with names like os-info-meeb322k y fs-pwn-meeb322k.
  • A single package, @nimbusedge/auth, shipped 39 versions in one day (September 11), all numbered 19999.x so they would outrank any legitimate internal version.
  • Dependency-confusion packages bearing corporate and internal-sounding names appeared every week: etoro-cashout, etoro-analytics y etoro-aggregator (Septiembre 11), concierge-sdk at 99.99.99 (Septiembre 13), @traktis/core (Septiembre de 17), y @dbbhk/ui-components, @siriusbeyond/* y @alphaspace/core at 99.x in the last week of the month.
  • The “siriusbeyond” operator started with a single unscoped package on September 20 and came back four days later as a scoped family (@siriusbeyond/auth, /ui, /utils), the same brand dressed as an internal package set.
  • Fake n8n workflow nodes recurred through the month, including n8n-nodes-sysdiag2, n8n-nodes-buildcheck y n8n-nodes-data-transformer-utils, continuing a pattern first seen in August.
  • An MCP client, mcp-consultasdeveiculos-client, was published in three versions on a single day (September 4), a reminder that the AI tooling layer is now part of the same supply chain.
  • Six numbered copies of simple-date-formatter-new-* (11 to 16) were published on September 25, a scripted burst built to test which names get through.

The defining pattern of September: attackers are no longer only borrowing trusted names, they are borrowing trusted positions. Plugins, workflow nodes, MCP clients and private package namespaces all run with more access than a typical dependency, and they are exactly where September’s campaigns concentrated.

A continuación se presenta un resumen de lo que encontramos. Puede ver los datos de las cuatro semanas divulgados en detalle en el Índice de Malicious Code Digest.

Week 5: 4 Packages Discovered

EcosistemaPREMIUMFecha
npm@alphaspace/core:99.0.126 de septiembre de 2026
npm@alphaspace/core:99.0.226 de septiembre de 2026
npm@alphaspace/core:99.0.326 de septiembre de 2026
npmcma-self-hosted-sandbox-cf:1.0.026 de septiembre de 2026

Semana 4: más de 24 paquetes descubiertos

EcosistemaPREMIUMConfirmado
npmtest890-auth:1.0.018 de septiembre de 2026
npmAgregar masivo SDK: 1.99.9919 de septiembre de 2026
npmnube-baileys:1.1.4119 de septiembre de 2026
npmbyted-commerce-materials:1.0.020 de septiembre de 2026
npmmi-seguimiento-automático:1.0.720 de septiembre de 2026
npmsiriusbeyond:1.0.020 de septiembre de 2026
npmsysverify:2.0.1022 de septiembre de 2026
npmn8n-nodes-data-transformer-utils:1.0.023 de septiembre de 2026
npmtake-home-caller-id:1.0.123 de septiembre de 2026
npm@dbbhk/ui-components:99.0.024 de septiembre de 2026
npm@siriusbeyond/auth:99.0.024 de septiembre de 2026
npm@alphaspace/core:99.0.225 de septiembre de 2026
npmformateador de fecha simple-nuevo-11:1.0.025 de septiembre de 2026

Semana 3: más de 81 paquetes descubiertos

EcosistemaPREMIUMConfirmado
pipilucy-python-script-2030:0.1.111 de septiembre de 2026
npm@nimbusedge/auth:19999.x (39 versiones)11 de septiembre de 2026
npmeToro-cashout:99.0.211 de septiembre de 2026
npmeToro-analytics:99.0.211 de septiembre de 2026
pipiaitextkit-py:0.1.111 de septiembre de 2026
npmnoblox-asset.js:7.4.012 de septiembre de 2026
npmconcierge-sdk:99.99.9913 de septiembre de 2026
pipidarkglitch:1.4.415 de septiembre de 2026
npmfs-pwn-meeb322k:1.0.015 de septiembre de 2026
npmstrapi-plugin-os-info-meeb322k:3.6.815 de septiembre de 2026
npmn8n-nodes-sysdiag2:2.0.215 de septiembre de 2026
npmn8n-nodes-buildcheck:1.0.015 de septiembre de 2026
npmcsa-mfa:1.1.1516 de septiembre de 2026
npmcomplemento-strapi-tryccresh-meeb:3.6.816 de septiembre de 2026
npm@traktis/core:99.99.217 de septiembre de 2026

Week 2: 13 Packages Discovered

EcosistemaPREMIUMFecha
pipisyswatch:1.0.007 de septiembre de 2026
pipisamaki:0.4.907 de septiembre de 2026
compositorSlimfit/Slimbase: 2.007 de septiembre de 2026
compositorSlimFit/Formbase: 1.207 de septiembre de 2026
compositorgcform/formhelper:1.207 de septiembre de 2026
npmnube-baileys:1.1.3907 de septiembre de 2026
npmaleación-graphql:1.0.108 de septiembre de 2026
npm@umschool/platform:999.0.010 de septiembre de 2026
npmtwilio-hackerone-poc-b8f21a:1.0.010 de septiembre de 2026
npmtwilio-hackerone-poc-b8f21a:1.0.110 de septiembre de 2026
npmnube-baileys:1.1.4011 de septiembre de 2026
pipidarkglitch:1.4.411 de septiembre de 2026
pipidarkglitch:1.4.511 de septiembre de 2026

Week 1: 18 Packages Discovered

EcosistemaPREMIUMConfirmado
npmamicat:1.0.001 de septiembre de 2026
npmbmcat:2.0.901 de septiembre de 2026
npmeyevox:1.0.001 de septiembre de 2026
npmmoidevh:1.0.001 de septiembre de 2026
npmmoidevk:1.0.001 de septiembre de 2026
npmmoidevl:1.0.001 de septiembre de 2026
pipisyswatch:1.0.002 de septiembre de 2026
npmnube-baileys:1.1.3702 de septiembre de 2026
npm@stellarshift/token-units:1.0.302 de septiembre de 2026
npm@stellarshift/evm-address-kit:1.0.302 de septiembre de 2026
npm@stellarshift/abi-tools:1.0.302 de septiembre de 2026
npm@stellarshift/chain-metadata:1.0.302 de septiembre de 2026
npm@a23842/dsh-notifier:0.1.003 de septiembre de 2026
pipisamaki:0.4.904 de septiembre de 2026
npmnube-baileys:1.1.3804 de septiembre de 2026
npmmcp-consultasdeveiculos-client:0.1.104 de septiembre de 2026
npmmcp-consultasdeveiculos-client:0.1.004 de septiembre de 2026
npmmcp-consultasdeveiculos-client:0.0.204 de septiembre de 2026

From Baileys to Strapi: What September’s Supply Chain Attacks Reveal

The campaigns above show attackers moving up the trust chain. A library impersonation that has now survived two months of takedowns, dependency-confusion packages inflating their version numbers to outrank private namespaces, and fake Strapi plugins, n8n nodes and MCP clients built to run where developers grant the most access: all of it lands in real SDLCs every week, often installed by automated tooling before any human reads the package name.

xygenis detección de malware y CI/CD and supply chain security give organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. MEW, Xygeni’s malware engine, detects malicious packages before a signature exists, across npm, PyPI, OpenVSX and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.

Cada hallazgo se prioriza automáticamente según su viabilidad, accesibilidad e impacto en el negocio, de modo que su equipo se centre en lo que realmente necesita solución, y no en lo que genera confusión.

Explore todos los paquetes y campañas maliciosas validadas por el equipo de seguridad de Xygeni en el Resumen de código malicioso.

Manténgase seguro. Manténgase rápido. Manténgase en control con Xygeni.

sca-tools-software-herramientas-de-analisis-de-composicion
Priorice, solucione y proteja sus riesgos de software
Obtén tu cuenta gratuita.
Sin tarjeta de crédito.

Asegure el desarrollo y la entrega de su software.

con la suite de productos Xygeni