Վնասակար կոդի ամփոփում հունիս

Վնասակար կոդի համառոտ ամսական ամփոփում՝ հուլիս

Welcome to the July edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed over 780 malicious packages across npm, PyPI, and OpenVSX (the VS Code extension marketplace), tracked across five weekly digests.

July was defined by three converging trends: sustained, high-volume version-flooding campaigns designed to outlast takedowns; a sharp escalation in attacks targeting AI tooling, MCP servers, and agentic workflows; and coordinated dependency-confusion campaigns against both enterprise namespaces and crypto/DeFi ecosystems.

Այս ամսվա ընթացքում գրանցված ամենանշանակալի արշավների շարքում են՝

  • bingo-ai on PyPI resurfaced twice, flooding the registry with well over 150 versions across two bursts (July 13 and July 21), confirming this is an ongoing operation, not a one-off.
  • zevairouter became July’s largest single-package campaign: over 65 versions across npm, published continuously from July 25–28.
  • gcli-control, the Windows RAT we profiled in detail that routes its C2 through npoint.io, escalated from version 0.1.0 to 0.13.0 across three separate weeks.
  • @szc-ft/mcp-szcd-client, the package behind SkillLeak, our writeup on a credential decryptor delivered through a bundled MCP skill, was confirmed July 2.
  • The week of July 7 brought the month’s heaviest AI-tooling targeting: mcp-server-pg, anthropic-toolkit, openai-agents-helpers, ollama-helpers, եւ @langgraphjs/toolkit, impersonating MCP, Anthropic, OpenAI, Ollama, and LangGraph.
  • A 17-package PayPal impersonation cluster hit npm July 27, all at version 28.0.0 within minutes.
  • @wagni_bot, roughly 60 npm packages impersonating crypto wallet SDKs (Ethereum, Solana, Binance, and more), all published in a single day, July 10.
  • Over a dozen fake VS Code extensions surfaced on OpenVSX, confirming attackers are expanding beyond package registries into the IDE itself.

The defining pattern of July: attacks increasingly target the AI agents and automated tooling that install packages with no human reviewer in the loop, at a publishing velocity built to outrun manual review.

Below is a summary of what we found. You can see all five weeks’ data disclosed in full detail at the Malicious Code Digest index.

Շաբաթ 5. Հայտնաբերվել է ավելի քան 180 փաթեթ

էկոհամակարգը Փաթեթ Հաստատված
npm@cryptosrvc/shift-sdk-v4:1.0.77Հուլ 24, 2026
openvsxcesium/gltf-vscode:0.0.1Հուլ 24, 2026
pypigcli-վերահսկողություն՝ 0.13.0Հուլ 24, 2026
vscodeairtune:1.0.0Հուլ 25, 2026
npmzevairouter:1.0.109Հուլ 25, 2026
npmidentityauthorizationserv:28.0.0Հուլ 27, 2026
npmmerchantprefsservice-paypal:28.0.0Հուլ 27, 2026
npmxo-member-components:28.0.0Հուլ 27, 2026
openvsxtechnosophos/vscode-helm:0.0.1Հուլ 27, 2026
openvsxbastienboutonnet/vscode-dbt:0.0.1Հուլ 27, 2026
npmmarkscan:1.0.0Հուլ 28, 2026
npmiphouse:1.0.0Հուլ 28, 2026
npmakrai-report-new:1.0.0Հուլ 28, 2026
pypivtranalytic:8.0.0Հուլ 28, 2026
npmgreatcall-customers-commandapi:99.0.0Հուլ 29, 2026
npmblots:2.1.1Հուլ 29, 2026
npm@ey-china/ey-assistant:1.0.1Հուլ 30, 2026
npmflydev:0.0.1Հուլ 30, 2026
npm@qtestorgz/sdk:1.0.0Հուլ 30, 2026

Շաբաթ 4. Հայտնաբերվել է ավելի քան 165 փաթեթ

էկոհամակարգը Փաթեթ Հաստատված
npmjavas-crypto:2.0.4Հուլ 17, 2026
npmclover-codelab-remote-pay-cloud:99.9.9Հուլ 17, 2026
npmհետևանքների ֆինանսներ՝ 99.0.0Հուլ 19, 2026
npmtwilio-առանց սերվերի: 99.99.99Հուլ 21, 2026
npmմատակարարման կենտրոն: 1.0.1Հուլ 21, 2026
npm@offa/offa-uwk:999.0.0Հուլ 21, 2026
npmամսաթվի-ֆորմատ-utils-xz:1.0.1Հուլ 21, 2026
pypiբինգո-աի:6.2.241Հուլ 21, 2026
npm@bpa-internal/bpa-utils:99.99.99Հուլ 22, 2026
npmn8n-հանգույցներ-pwn:1.0.1Հուլ 22, 2026
pypigcli-վերահսկողություն՝ 0.1.0Հուլ 22, 2026
npmuniswap-sdk-v4:1.0.0Հուլ 23, 2026
npmwagmi-react:1.0.0Հուլ 23, 2026
npmեթերների անվտանգություն՝ 1.0.0Հուլ 23, 2026
pypigcli-վերահսկողություն՝ 0.12.0Հուլ 24, 2026
npmdatefmt-pro:1.0.1Հուլ 24, 2026
npm@daylightqc/date-fmt-lite:1.0.0Հուլ 24, 2026

Շաբաթ 3. Հայտնաբերվել է ավելի քան 145 փաթեթ

էկոհամակարգը Փաթեթ Հաստատված
npmenv-fast:1.0.0Հուլ 11, 2026
pypiլուսին-ուլտրամանուշակագույն: 0.0.25Հուլ 12, 2026
npmgoogle-caja-bower: 1000.800.20Հուլ 13, 2026
npmխոցելիության փաթեթ՝ 99.9.14Հուլ 13, 2026
pypiբինգո-աի:6.2.109Հուլ 13, 2026
npmbugexploit:99.9.9Հուլ 13, 2026
npmamdocs-core-փաթեթ:11.11.11Հուլ 14, 2026
npmarb-kit:1.0.0Հուլ 14, 2026
npmsolana-key-utils:1.0.0Հուլ 14, 2026
npmaxios-test-one:1.18.9Հուլ 15, 2026
pypiպլուներհաքեր: 2.0.1Հուլ 15, 2026
pypilog-guru:0.7.8Հուլ 16, 2026
pypiպիլոգորա՝ 0.7.8Հուլ 16, 2026
npm@across-toolkit/eslint-config:99.0.0Հուլ 17, 2026
npmvalidpilot-mcp:1.4.0Հուլ 17, 2026
npmՆիքսորա: 26.7.17Հուլ 17, 2026

Շաբաթ 2. Հայտնաբերվել է ավելի քան 200 փաթեթ

էկոհամակարգը Փաթեթ Հաստատված
pypiprocwire:5.2.7Հուլ 4, 2026
npmնեոնային տերմինալ՝ 0.3.0Հուլ 4, 2026
npmnolimit-agent: 1.0.336Հուլ 6, 2026
vscodeandroid-support-framework-vs:0.0.1Հուլ 6, 2026
npmmcp-սերվեր-pg:1.0.0Հուլ 7, 2026
npmանթրոպիկ-գործիքակազմ՝ 1.3.1Հուլ 7, 2026
npmopenai-գործակալների օգնականներ՝ 1.3.3Հուլ 7, 2026
npmdebugcli:4.4.1Հուլ 7, 2026
npmhello244a:1.0.38Հուլ 7, 2026
npmորոտ-րոնի: 99.9.9Հուլ 8, 2026
pypiլուսին-ուլտրամանուշակագույն: 0.0.5Հուլ 9, 2026
npmes6-կոդավորել:2.0.0Հուլ 9, 2026
npmn8n-հանգույցներ-mcputils:0.1.4Հուլ 9, 2026
npm@wagni_bot/hyperliquid-sdk:1.0.0Հուլ 10, 2026
npm@wagni_bot/metemask-sdk:1.0.0Հուլ 10, 2026
npm@wagni_bot/pumpfun-sdk:1.0.0Հուլ 10, 2026
npm@wagni_bot/binance-sdk:1.0.0Հուլ 10, 2026
npm@wagni_bot/ethereum-wallet:1.0.0Հուլ 10, 2026
npmթեստավորում-d3do:99.9.9Հուլ 10, 2026
npmclient-cookies-agent:99.9.6Հուլ 10, 2026

Շաբաթ 1. Հայտնաբերվել է ավելի քան 90 փաթեթ

էկոհամակարգը Փաթեթ Հաստատված
npmանիծված մոդուլներ՝ 999.1.2Հուլ 1, 2026
npm@szc-ft/mcp-szcd-client:0.39.0Հուլ 2, 2026
npmpp-react-v5:30.0.2Հուլ 1, 2026
npmաստղակերպեր՝ 0.5.1Հուլ 1, 2026
npmdate-fns-lite:1.0.9Հուլ 2, 2026
npm@easypayment/medusa-paypal:0.7.6Հուլ 2, 2026
npmdl-pp-latm:80.4.2Հուլ 2, 2026
npm@sudoughnym/enviro-demo:99.99.99Հուլ 1, 2026
npmnolimit-agent: 1.0.316Հուլ 2, 2026
npmանիծված-ecto-d3ab00:1.0.0Հուլ 3, 2026
npm@checkrhq/adjudication-api-client:0.0.2Հուլ 3, 2026

From Version Storms to AI Impersonation: What July’s Supply Chain Attacks Reveal

The campaigns above aren’t edge cases, they’re the baseline now. Version-flooding storms, coordinated impersonation drops, and AI-tooling lookalikes are hitting real teams in real SDLCs every week, often with no human in the loop between publication and install.

Քսիգենիի չարամիտ ծրագրերի հայտնաբերում և supply chain security platform gives organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. Coverage spans npm, PyPI, OpenVSX, and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.

Յուրաքանչյուր գտածո ավտոմատ կերպով առաջնահերթություն է տրվում՝ հիմնվելով շահագործելիության, հասանելիության և բիզնեսի վրա ազդեցության վրա, ուստի ձեր թիմը կենտրոնանում է այն բանի վրա, ինչը իրականում կարիք ունի շտկելու, այլ ոչ թե աղմուկի վրա։

Ուսումնասիրեք Xygeni-ի անվտանգության թիմի կողմից հաստատված յուրաքանչյուր վնասակար փաթեթ և արշավ Վնասակար կոդի համառոտագիր.

Մնացեք անվտանգ։ Մնացեք արագ։ Մնացեք վերահսկողության տակ Xygeni-ի հետ։

sca-tools-software-composition-analysis-tools
Առաջնահերթություն տվեք, շտկեք և պաշտպանեք ձեր ծրագրային ռիսկերը
Ստացեք ձեր անվճար հաշիվը։
Ոչ մի վարկային քարտ չի պահանջվում:

Ապահովեք ձեր ծրագրային ապահովման մշակումը և մատակարարումը

Xygeni Product Suite-ի հետ