Welcome to the July edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed over 780 malicious packages across npm, PyPI, and OpenVSX (the VS Code extension marketplace), tracked across five weekly digests.
July was defined by three converging trends: sustained, high-volume version-flooding campaigns designed to outlast takedowns; a sharp escalation in attacks targeting AI tooling, MCP servers, and agentic workflows; and coordinated dependency-confusion campaigns against both enterprise namespaces and crypto/DeFi ecosystems.
Među najznačajnijim kampanjama dokumentiranim ovog mjeseca:
bingo-aion PyPI resurfaced twice, flooding the registry with well over 150 versions across two bursts (July 13 and July 21), confirming this is an ongoing operation, not a one-off.zevairouterbecame July’s largest single-package campaign: over 65 versions across npm, published continuously from July 25–28.gcli-control, the Windows RAT we profiled in detail that routes its C2 through npoint.io, escalated from version 0.1.0 to 0.13.0 across three separate weeks.@szc-ft/mcp-szcd-client, the package behind SkillLeak, our writeup on a credential decryptor delivered through a bundled MCP skill, was confirmed July 2.- The week of July 7 brought the month’s heaviest AI-tooling targeting:
mcp-server-pg,anthropic-toolkit,openai-agents-helpers,ollama-helpersi@langgraphjs/toolkit, impersonating MCP, Anthropic, OpenAI, Ollama, and LangGraph. - A 17-package PayPal impersonation cluster hit npm July 27, all at version 28.0.0 within minutes.
@wagni_bot, roughly 60 npm packages impersonating crypto wallet SDKs (Ethereum, Solana, Binance, and more), all published in a single day, July 10.- Over a dozen fake VS Code extensions surfaced on OpenVSX, confirming attackers are expanding beyond package registries into the IDE itself.
The defining pattern of July: attacks increasingly target the AI agents and automated tooling that install packages with no human reviewer in the loop, at a publishing velocity built to outrun manual review.
Below is a summary of what we found. You can see all five weeks’ data disclosed in full detail at the Malicious Code Digest index.
5. tjedan: Otkriveno preko 180 paketa
| ekosustav | Paket | potvrđen |
|---|---|---|
| NPM | @cryptosrvc/shift-sdk-v4:1.0.77 | Srpnja 24, 2026 |
| openvsx | cesium/gltf-vscode:0.0.1 | Srpnja 24, 2026 |
| pypi | gcli-control:0.13.0 | Srpnja 24, 2026 |
| vscode | airtune:1.0.0 | Srpnja 25, 2026 |
| NPM | zevairouter:1.0.109 | Srpnja 25, 2026 |
| NPM | identityauthorizationserv:28.0.0 | Srpnja 27, 2026 |
| NPM | merchantprefsservice-paypal:28.0.0 | Srpnja 27, 2026 |
| NPM | xo-member-components:28.0.0 | Srpnja 27, 2026 |
| openvsx | technosophos/vscode-helm:0.0.1 | Srpnja 27, 2026 |
| openvsx | bastienboutonnet/vscode-dbt:0.0.1 | Srpnja 27, 2026 |
| NPM | markscan:1.0.0 | Srpnja 28, 2026 |
| NPM | iphouse:1.0.0 | Srpnja 28, 2026 |
| NPM | akrai-report-new:1.0.0 | Srpnja 28, 2026 |
| pypi | vtranalytic:8.0.0 | Srpnja 28, 2026 |
| NPM | greatcall-customers-commandapi:99.0.0 | Srpnja 29, 2026 |
| NPM | blots:2.1.1 | Srpnja 29, 2026 |
| NPM | @ey-china/ey-assistant:1.0.1 | Srpnja 30, 2026 |
| NPM | flydev:0.0.1 | Srpnja 30, 2026 |
| NPM | @qtestorgz/sdk:1.0.0 | Srpnja 30, 2026 |
4. tjedan: Otkriveno preko 165 paketa
| ekosustav | Paket | potvrđen |
|---|---|---|
| NPM | javas-crypto:2.0.4 | Srpnja 17, 2026 |
| NPM | clover-codelab-remote-pay-cloud:99.9.9 | Srpnja 17, 2026 |
| NPM | nakon-financiranja:99.0.0 | Srpnja 19, 2026 |
| NPM | twilio-serverless:99.99.99 | Srpnja 21, 2026 |
| NPM | supplyhub:1.0.1 | Srpnja 21, 2026 |
| NPM | @offa/offa-uwk:999.0.0 | Srpnja 21, 2026 |
| NPM | alati za format-datuma-xz:1.0.1 | Srpnja 21, 2026 |
| pypi | bingo-ai:6.2.241 | Srpnja 21, 2026 |
| NPM | @bpa-internal/bpa-utils:99.99.99 | Srpnja 22, 2026 |
| NPM | n8n-čvorovi-pwn:1.0.1 | Srpnja 22, 2026 |
| pypi | gcli-control:0.1.0 | Srpnja 22, 2026 |
| NPM | uniswap-sdk-v4:1.0.0 | Srpnja 23, 2026 |
| NPM | wagmi-react:1.0.0 | Srpnja 23, 2026 |
| NPM | ethers-secure:1.0.0 | Srpnja 23, 2026 |
| pypi | gcli-control:0.12.0 | Srpnja 24, 2026 |
| NPM | datefmt-pro:1.0.1 | Srpnja 24, 2026 |
| NPM | @daylightqc/date-fmt-lite:1.0.0 | Srpnja 24, 2026 |
3. tjedan: Otkriveno preko 145 paketa
| ekosustav | Paket | potvrđen |
|---|---|---|
| NPM | env-fast:1.0.0 | Srpnja 11, 2026 |
| pypi | moon-uv:0.0.25 | Srpnja 12, 2026 |
| NPM | google-caja-bower:1000.800.20 | Srpnja 13, 2026 |
| NPM | vuln-package:99.9.14 | Srpnja 13, 2026 |
| pypi | bingo-ai:6.2.109 | Srpnja 13, 2026 |
| NPM | bugeexploit:99.9.9 | Srpnja 13, 2026 |
| NPM | amdocs-core-package:11.11.11 | Srpnja 14, 2026 |
| NPM | arb-kit:1.0.0 | Srpnja 14, 2026 |
| NPM | solana-key-utils:1.0.0 | Srpnja 14, 2026 |
| NPM | axios-test-jedan:1.18.9 | Srpnja 15, 2026 |
| pypi | plungerhacker:2.0.1 | Srpnja 15, 2026 |
| pypi | log-guru:0.7.8 | Srpnja 16, 2026 |
| pypi | pilogora: 0.7.8 | Srpnja 16, 2026 |
| NPM | @across-toolkit/eslint-config:99.0.0 | Srpnja 17, 2026 |
| NPM | validpilot-mcp:1.4.0 | Srpnja 17, 2026 |
| NPM | nyxora:26.7.17 | Srpnja 17, 2026 |
2. tjedan: Otkriveno preko 200 paketa
| ekosustav | Paket | potvrđen |
|---|---|---|
| pypi | procwire:5.2.7 | Srpnja 4, 2026 |
| NPM | neonski terminal: 0.3.0 | Srpnja 4, 2026 |
| NPM | nolimit-agent:1.0.336 | Srpnja 6, 2026 |
| vscode | android-support-framework-vs:0.0.1 | Srpnja 6, 2026 |
| NPM | mcp-server-pg:1.0.0 | Srpnja 7, 2026 |
| NPM | antropski-pribor:1.3.1 | Srpnja 7, 2026 |
| NPM | openai-agents-helpers:1.3.3 | Srpnja 7, 2026 |
| NPM | debugcli:4.4.1 | Srpnja 7, 2026 |
| NPM | hello244a:1.0.38 | Srpnja 7, 2026 |
| NPM | gromoglasan: 99.9.9 | Srpnja 8, 2026 |
| pypi | moon-uv:0.0.5 | Srpnja 9, 2026 |
| NPM | es6-codify:2.0.0 | Srpnja 9, 2026 |
| NPM | n8n-čvorovi-mcputils:0.1.4 | Srpnja 9, 2026 |
| NPM | @wagni_bot/hyperliquid-sdk:1.0.0 | Srpnja 10, 2026 |
| NPM | @wagni_bot/metemask-sdk:1.0.0 | Srpnja 10, 2026 |
| NPM | @wagni_bot/pumpfun-sdk:1.0.0 | Srpnja 10, 2026 |
| NPM | @wagni_bot/binance-sdk:1.0.0 | Srpnja 10, 2026 |
| NPM | @wagni_bot/ethereum-novčanik:1.0.0 | Srpnja 10, 2026 |
| NPM | testiranje-d3do:99.9.9 | Srpnja 10, 2026 |
| NPM | klijent-kolačići-agent:99.9.6 | Srpnja 10, 2026 |
1. tjedan: Otkriveno preko 90 paketa
| ekosustav | Paket | potvrđen |
|---|---|---|
| NPM | prokleti-moduli:999.1.2 | Srpnja 1, 2026 |
| NPM | @szc-ft/mcp-szcd-klijent:0.39.0 | Srpnja 2, 2026 |
| NPM | pp-react-v5:30.0.2 | Srpnja 1, 2026 |
| NPM | konstelacije:0.5.1 | Srpnja 1, 2026 |
| NPM | date-fns-lite:1.0.9 | Srpnja 2, 2026 |
| NPM | @easypayment/medusa-paypal:0.7.6 | Srpnja 2, 2026 |
| NPM | dl-pp-latm:80.4.2 | Srpnja 2, 2026 |
| NPM | @sudoughnym/enviro-demo:99.99.99 | Srpnja 1, 2026 |
| NPM | nolimit-agent:1.0.316 | Srpnja 2, 2026 |
| NPM | prokleti-ecto-d3ab00:1.0.0 | Srpnja 3, 2026 |
| NPM | @checkrhq/adjudication-api-client:0.0.2 | Srpnja 3, 2026 |
From Version Storms to AI Impersonation: What July’s Supply Chain Attacks Reveal
The campaigns above aren’t edge cases, they’re the baseline now. Version-flooding storms, coordinated impersonation drops, and AI-tooling lookalikes are hitting real teams in real SDLCs every week, often with no human in the loop between publication and install.
Xygenijev otkrivanje zlonamjernog softvera i supply chain security platform gives organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. Coverage spans npm, PyPI, OpenVSX, and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.
Svakom nalazu se automatski daje prioritet prema iskoristivosti, dostupnosti i utjecaju na poslovanje, tako da se vaš tim usredotočuje na ono što zapravo treba popraviti, a ne na buku.
Istražite svaki zlonamjerni paket i kampanju koju je potvrdio Xygenijev sigurnosni tim u Sažetak zlonamjernog koda.
Ostanite sigurni. Ostanite brzi. Ostanite pod kontrolom uz Xygeni.




