Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 53 malicious packages between August 21 and August 28, 2026, led by a continuation of the Baileys impersonation campaign flagged last week, a cluster of seven identically-versioned e-commerce-branded packages published in a single day, and a wave of authentication-themed packages (TOTP, 2FA, OTP) spread across five separate naming variants.
The Baileys impersonation continued under @vanzxy/baileys, with seven new versions (1.4.3 through 1.4.9) confirmed between August 22 and 23, the same rapid-iteration pattern seen the week prior.
A cluster of seven packages (sm-billing-form, sm-cart, sm-payment, sm-checkout, sm-session, sm-admin, sm-apikey-model) were all published at the identical version 99.0.1 on August 24, an unusual shared version number across supposedly independent, e-commerce-themed package names.
Also worth flagging: a spread of authentication-related package names, totp-utils, Secreto-key-totp, Secretokey-2fa, Secretokey2fa, y 2fa-Secretokey, appeared across the week under different naming conventions but a shared theme, alongside auth-otp, which published five versions in a single day (August 24).
Esta instantánea semanal es parte de nuestro trabajo continuo Resumen de código maliciosodonde validamos nuevas amenazas para ayudar a los equipos de DevSecOps a proteger sus pipelines antes de que se produzcan daños.
| Ecosistema | PREMIUM | Fecha |
|---|---|---|
| npm | totp-utils:1.4.3 | 21 de agosto de 2026 |
| npm | totp-utils:1.4.4 | 21 de agosto de 2026 |
| npm | @vanzxy/baileys:1.4.3 | 22 de agosto de 2026 |
| npm | @vanzxy/baileys:1.4.4 | 22 de agosto de 2026 |
| npm | totp-utils:1.4.5 | 23 de agosto de 2026 |
| npm | totp-utils:1.4.8 | 23 de agosto de 2026 |
| npm | totp-utils:1.4.7 | 23 de agosto de 2026 |
| npm | totp-utils:1.4.6 | 23 de agosto de 2026 |
| npm | totp-utils:1.4.9 | 23 de agosto de 2026 |
| npm | @vanzxy/baileys:1.4.5 | 23 de agosto de 2026 |
| pipi | kisama:0.4.6 | 23 de agosto de 2026 |
| npm | @vanzxy/baileys:1.4.6 | 23 de agosto de 2026 |
| npm | @vanzxy/baileys:1.4.7 | 23 de agosto de 2026 |
| npm | @vanzxy/baileys:1.4.8 | 23 de agosto de 2026 |
| npm | @vanzxy/baileys:1.4.9 | 23 de agosto de 2026 |
| pipi | mlflow-otel-instrumentor:1.1.0 | 23 de agosto de 2026 |
| npm | Secreto-key-totp:1.5.1 | 23 de agosto de 2026 |
| pipi | envprovision:1.4.0 | 23 de agosto de 2026 |
| pipi | envprovision:1.3.0 | 23 de agosto de 2026 |
| npm | sm-billing-form:99.0.1 | 24 de agosto de 2026 |
| npm | sm-cart:99.0.1 | 24 de agosto de 2026 |
| npm | sm-payment:99.0.1 | 24 de agosto de 2026 |
| npm | sm-checkout:99.0.1 | 24 de agosto de 2026 |
| npm | sm-session:99.0.1 | 24 de agosto de 2026 |
| npm | sm-admin:99.0.1 | 24 de agosto de 2026 |
| npm | sm-apikey-model:99.0.1 | 24 de agosto de 2026 |
| npm | dotish:1.0.0 | 24 de agosto de 2026 |
| npm | openai-pr-reviewer:1.0.0 | 24 de agosto de 2026 |
| npm | remove-bg-serverless-azure:1.0.1 | 24 de agosto de 2026 |
| npm | auth-otp:1.0.3 | 24 de agosto de 2026 |
| npm | auth-otp:1.0.2 | 24 de agosto de 2026 |
| npm | auth-otp:1.0.1 | 24 de agosto de 2026 |
| npm | auth-otp:1.0.4 | 24 de agosto de 2026 |
| npm | auth-otp:1.0.5 | 24 de agosto de 2026 |
| npm | Secretokey-2fa:1.0.1 | 24 de agosto de 2026 |
| pipi | minecraft-ytreceiver:0.1.0 | 25 de agosto de 2026 |
| pipi | minecraft-ytreceiver:0.2.0 | 25 de agosto de 2026 |
| pipi | minecraft-ytreceiver:0.4.0 | 25 de agosto de 2026 |
| pipi | minecraft-ytreceiver:0.3.0 | 25 de agosto de 2026 |
| pipi | minecraft-ytreceiver:0.5.0 | 25 de agosto de 2026 |
| npm | moidevz:1.0.0 | 26 de agosto de 2026 |
| npm | nube-baileys:1.1.36 | 26 de agosto de 2026 |
| npm | zenntechinc-cli:1.6.6 | 26 de agosto de 2026 |
| npm | zenntechinc-cli:1.6.4 | 26 de agosto de 2026 |
| npm | mt-ts-serverless-starter:1.0.1 | 26 de agosto de 2026 |
| npm | octopus-action:1.0.1 | 26 de agosto de 2026 |
| npm | Secretokey2fa:1.0.1 | 26 de agosto de 2026 |
| npm | moideva:1.0.0 | 27 de agosto de 2026 |
| npm | vs-modules:1.2.2 | 27 de agosto de 2026 |
| npm | rn-push-provisioning:99.0.1 | 27 de agosto de 2026 |
| npm | 2fa-Secretokey:1.0.5 | 28 de agosto de 2026 |
| npm | 2fa-Secretokey:1.0.6 | 28 de agosto de 2026 |
| npm | 2fa-Secretokey:1.0.7 | 28 de agosto de 2026 |
Same Version, Seven Names: 53 Malicious Packages This Week
This week’s digest shows the same pressure from two different angles: a campaign still iterating on an old alias, and a fresh cluster hiding behind a shared, unusual detail.
The Baileys impersonation campaign flagged last week hasn’t stopped. @vanzxy/baileys published seven new versions (1.4.3 through 1.4.9) between August 22 and 23, the same climbing-version pattern seen the week before under a different alias, consistent with an attacker adjusting the package name rather than abandoning the attempt after detection.
A separate cluster gave itself away through version numbers rather than names. Seven e-commerce-branded packages (sm-billing-form, sm-cart, sm-payment, sm-checkout, sm-session, sm-admin, sm-apikey-model) all shipped under the identical version 99.0.1 on August 24, an unusual coincidence across supposedly independent projects that points to one actor behind all seven. A separate wave of authentication-themed packages, totp-utils, Secreto-key-totp, Secretokey-2fa, Secretokey2fa, y 2fa-Secretokey, spread the same theme across five different naming conventions over the week, with auth-otp alone publishing five versions in a single day.
Alerta temprana de malware de Xygeni monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When seven unrelated-looking package names publish under the same version number on the same day, or a campaign resurfaces under a new alias a week after the last one, detection that only checks once is already behind.
xygenis Open Source Security La plataforma brinda a los equipos de DevSecOps la detección y priorización en tiempo real necesarias para mantenerse a la vanguardia de la presión coordinada de la cadena de suministro, por lo que su pipelineMantén la limpieza sin ralentizar a tus equipos.





