Welcome to the September edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed 104 malicious packages across npm and PyPI, tracked across four weekly digests.
September was defined by three converging trends: campaigns that carried straight over from August and kept going despite takedowns; dependency confusion at scale, with dozens of packages claiming inflated version numbers like 99.0.0 y 19999.x to hijack private namespaces; and a clear move toward the plugin and automation ecosystems developers trust with privileged access, such as Strapi, n8n and MCP.
Entre las campañas más destacadas documentadas este mes:
- El self-deleting anti-proctoring operator returned on September 1, with
amicat,bmcat,eyevoxymoidevhconfirmed alongside two new names from the same stem,moidevkymoidevl. - Baileys, the WhatsApp Web API library impersonated throughout August, stayed under attack:
cloud-baileysreached versions1.1.37y1.1.38in the first week and1.1.41by September 19, making it one of the longest-running impersonations we have tracked. - A 21-package campaign (September 15 to 17) published fake Strapi plugins under the “meeb” tag, all at the identical version
3.6.8, alongside companion packages with names likeos-info-meeb322kyfs-pwn-meeb322k. - A single package,
@nimbusedge/auth, shipped 39 versions in one day (September 11), all numbered19999.xso they would outrank any legitimate internal version. - Dependency-confusion packages bearing corporate and internal-sounding names appeared every week:
etoro-cashout,etoro-analyticsyetoro-aggregator(Septiembre 11),concierge-sdkat99.99.99(Septiembre 13),@traktis/core(Septiembre de 17), y@dbbhk/ui-components,@siriusbeyond/*y@alphaspace/coreat99.xin the last week of the month. - The “siriusbeyond” operator started with a single unscoped package on September 20 and came back four days later as a scoped family (
@siriusbeyond/auth,/ui,/utils), the same brand dressed as an internal package set. - Fake n8n workflow nodes recurred through the month, including
n8n-nodes-sysdiag2,n8n-nodes-buildcheckyn8n-nodes-data-transformer-utils, continuing a pattern first seen in August. - An MCP client,
mcp-consultasdeveiculos-client, was published in three versions on a single day (September 4), a reminder that the AI tooling layer is now part of the same supply chain. - Six numbered copies of
simple-date-formatter-new-*(11 to 16) were published on September 25, a scripted burst built to test which names get through.
The defining pattern of September: attackers are no longer only borrowing trusted names, they are borrowing trusted positions. Plugins, workflow nodes, MCP clients and private package namespaces all run with more access than a typical dependency, and they are exactly where September’s campaigns concentrated.
A continuación se presenta un resumen de lo que encontramos. Puede ver los datos de las cuatro semanas divulgados en detalle en el Índice de Malicious Code Digest.
Week 5: 4 Packages Discovered
| Ecosistema | PREMIUM | Fecha |
|---|---|---|
| npm | @alphaspace/core:99.0.1 | 26 de septiembre de 2026 |
| npm | @alphaspace/core:99.0.2 | 26 de septiembre de 2026 |
| npm | @alphaspace/core:99.0.3 | 26 de septiembre de 2026 |
| npm | cma-self-hosted-sandbox-cf:1.0.0 | 26 de septiembre de 2026 |
Semana 4: más de 24 paquetes descubiertos
| Ecosistema | PREMIUM | Confirmado |
|---|---|---|
| npm | test890-auth:1.0.0 | 18 de septiembre de 2026 |
| npm | Agregar masivo SDK: 1.99.99 | 19 de septiembre de 2026 |
| npm | nube-baileys:1.1.41 | 19 de septiembre de 2026 |
| npm | byted-commerce-materials:1.0.0 | 20 de septiembre de 2026 |
| npm | mi-seguimiento-automático:1.0.7 | 20 de septiembre de 2026 |
| npm | siriusbeyond:1.0.0 | 20 de septiembre de 2026 |
| npm | sysverify:2.0.10 | 22 de septiembre de 2026 |
| npm | n8n-nodes-data-transformer-utils:1.0.0 | 23 de septiembre de 2026 |
| npm | take-home-caller-id:1.0.1 | 23 de septiembre de 2026 |
| npm | @dbbhk/ui-components:99.0.0 | 24 de septiembre de 2026 |
| npm | @siriusbeyond/auth:99.0.0 | 24 de septiembre de 2026 |
| npm | @alphaspace/core:99.0.2 | 25 de septiembre de 2026 |
| npm | formateador de fecha simple-nuevo-11:1.0.0 | 25 de septiembre de 2026 |
Semana 3: más de 81 paquetes descubiertos
| Ecosistema | PREMIUM | Confirmado |
|---|---|---|
| pipi | lucy-python-script-2030:0.1.1 | 11 de septiembre de 2026 |
| npm | @nimbusedge/auth:19999.x (39 versiones) | 11 de septiembre de 2026 |
| npm | eToro-cashout:99.0.2 | 11 de septiembre de 2026 |
| npm | eToro-analytics:99.0.2 | 11 de septiembre de 2026 |
| pipi | aitextkit-py:0.1.1 | 11 de septiembre de 2026 |
| npm | noblox-asset.js:7.4.0 | 12 de septiembre de 2026 |
| npm | concierge-sdk:99.99.99 | 13 de septiembre de 2026 |
| pipi | darkglitch:1.4.4 | 15 de septiembre de 2026 |
| npm | fs-pwn-meeb322k:1.0.0 | 15 de septiembre de 2026 |
| npm | strapi-plugin-os-info-meeb322k:3.6.8 | 15 de septiembre de 2026 |
| npm | n8n-nodes-sysdiag2:2.0.2 | 15 de septiembre de 2026 |
| npm | n8n-nodes-buildcheck:1.0.0 | 15 de septiembre de 2026 |
| npm | csa-mfa:1.1.15 | 16 de septiembre de 2026 |
| npm | complemento-strapi-tryccresh-meeb:3.6.8 | 16 de septiembre de 2026 |
| npm | @traktis/core:99.99.2 | 17 de septiembre de 2026 |
Week 2: 13 Packages Discovered
| Ecosistema | PREMIUM | Fecha |
|---|---|---|
| pipi | syswatch:1.0.0 | 07 de septiembre de 2026 |
| pipi | samaki:0.4.9 | 07 de septiembre de 2026 |
| compositor | Slimfit/Slimbase: 2.0 | 07 de septiembre de 2026 |
| compositor | SlimFit/Formbase: 1.2 | 07 de septiembre de 2026 |
| compositor | gcform/formhelper:1.2 | 07 de septiembre de 2026 |
| npm | nube-baileys:1.1.39 | 07 de septiembre de 2026 |
| npm | aleación-graphql:1.0.1 | 08 de septiembre de 2026 |
| npm | @umschool/platform:999.0.0 | 10 de septiembre de 2026 |
| npm | twilio-hackerone-poc-b8f21a:1.0.0 | 10 de septiembre de 2026 |
| npm | twilio-hackerone-poc-b8f21a:1.0.1 | 10 de septiembre de 2026 |
| npm | nube-baileys:1.1.40 | 11 de septiembre de 2026 |
| pipi | darkglitch:1.4.4 | 11 de septiembre de 2026 |
| pipi | darkglitch:1.4.5 | 11 de septiembre de 2026 |
Week 1: 18 Packages Discovered
| Ecosistema | PREMIUM | Confirmado |
|---|---|---|
| npm | amicat:1.0.0 | 01 de septiembre de 2026 |
| npm | bmcat:2.0.9 | 01 de septiembre de 2026 |
| npm | eyevox:1.0.0 | 01 de septiembre de 2026 |
| npm | moidevh:1.0.0 | 01 de septiembre de 2026 |
| npm | moidevk:1.0.0 | 01 de septiembre de 2026 |
| npm | moidevl:1.0.0 | 01 de septiembre de 2026 |
| pipi | syswatch:1.0.0 | 02 de septiembre de 2026 |
| npm | nube-baileys:1.1.37 | 02 de septiembre de 2026 |
| npm | @stellarshift/token-units:1.0.3 | 02 de septiembre de 2026 |
| npm | @stellarshift/evm-address-kit:1.0.3 | 02 de septiembre de 2026 |
| npm | @stellarshift/abi-tools:1.0.3 | 02 de septiembre de 2026 |
| npm | @stellarshift/chain-metadata:1.0.3 | 02 de septiembre de 2026 |
| npm | @a23842/dsh-notifier:0.1.0 | 03 de septiembre de 2026 |
| pipi | samaki:0.4.9 | 04 de septiembre de 2026 |
| npm | nube-baileys:1.1.38 | 04 de septiembre de 2026 |
| npm | mcp-consultasdeveiculos-client:0.1.1 | 04 de septiembre de 2026 |
| npm | mcp-consultasdeveiculos-client:0.1.0 | 04 de septiembre de 2026 |
| npm | mcp-consultasdeveiculos-client:0.0.2 | 04 de septiembre de 2026 |
From Baileys to Strapi: What September’s Supply Chain Attacks Reveal
The campaigns above show attackers moving up the trust chain. A library impersonation that has now survived two months of takedowns, dependency-confusion packages inflating their version numbers to outrank private namespaces, and fake Strapi plugins, n8n nodes and MCP clients built to run where developers grant the most access: all of it lands in real SDLCs every week, often installed by automated tooling before any human reads the package name.
xygenis detección de malware y CI/CD and supply chain security give organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. MEW, Xygeni’s malware engine, detects malicious packages before a signature exists, across npm, PyPI, OpenVSX and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.
Cada hallazgo se prioriza automáticamente según su viabilidad, accesibilidad e impacto en el negocio, de modo que su equipo se centre en lo que realmente necesita solución, y no en lo que genera confusión.
Explore todos los paquetes y campañas maliciosas validadas por el equipo de seguridad de Xygeni en el Resumen de código malicioso.
Manténgase seguro. Manténgase rápido. Manténgase en control con Xygeni.







