როგორც ყოველ კვირას, ჩვენი მავნე პროგრამების აღმოჩენის სისტემები საჯარო რეესტრებში ათასობით ახალ და განახლებულ პაკეტს სკანირებენ. We confirmed 81 malicious package versions between September 11 and 17, 2026, with a single npm package flooding the registry with 39 versions in under half an hour, a plugin-naming campaign that is still uploading as this goes out, and four separate actors reaching for the same version-inflation trick.
@nimbusedge/auth accounts for 39 of this week’s confirmations on its own, published as versions in the 19999.x range within roughly twenty minutes on September 11. Publishing that many versions that fast is not an attempt at credibility, it is an attempt to sit above whatever an internal package resolves to. Separately, 21 packages sharing the meeb322k მდე meeb suffixes appeared across three consecutive days, almost all of them following Strapi plugin naming conventions and pinned to the same 3.6.8 version. The uploads continued through September 17, which makes this an active campaign rather than a batch.
ასევე აღსანიშნავია: concierge-sdk at 99.99.99 and 99.99.100, @traktis/core მდე @traktis/environment at 99.99.2, and three etoro- prefixed packages at 99.0.2 all reached for inflated version numbers in the same week, alongside the nimbusedge case. Two packages targeted n8n node naming (n8n-nodes-sysdiag2, n8n-nodes-buildcheck), და darkglitch on PyPI shipped 1.4.4 and 1.4.5 back-to-back.
ეს ყოველკვირეული მიმოხილვა ჩვენი მიმდინარე გეგმის ნაწილია მავნე კოდის დაიჯესტი, სადაც ჩვენ ვამოწმებთ ახალ საფრთხეებს, რათა დავეხმაროთ DevSecOps გუნდებს დაიცვან თავიანთი pipelineდაზიანების მოხდენამდე.
Four Actors, One Trick: 81 Malicious Package Versions This Week
This week’s digest shows volume being used as a weapon: a single package published 39 times in twenty minutes, a plugin-naming campaign still uploading on the day we published, and four separate actors reaching for the same inflated version numbers.
@nimbusedge/auth shipped 39 versions in the 19999.x range in under half an hour, which is not an attempt to look legitimate but an attempt to sit above whatever an internal package resolves to. The meeb cluster took the opposite approach: 21 packages following Strapi plugin naming conventions, all pinned to 3.6.8, drip-fed across three consecutive days and still going. And concierge-sdk, @traktis/core, სამი etoro- packages and nimbusedge all used the same inflated-version tactic in the same week, which tells you it is working often enough to be worth repeating.
Xygeni-ის ადრეული მავნე პროგრამების გაფრთხილება monitors npm, PyPI, Maven, Composer, OpenVSX, and other registries in real time, flagging threats at publication, before they reach a build and before an AI agent installs them autonomously. When one actor can publish 39 versions in twenty minutes, detection that waits for a signature is not late by days, it is late by the entire attack.
ქსიგენი Open Source Security პლატფორმა DevSecOps გუნდებს რეალურ დროში აღმოჩენისა და პრიორიტეტების განსაზღვრის საშუალებას აძლევს, რათა წინ უსწრებდნენ მიწოდების ჯაჭვზე არსებულ კოორდინირებულ ზეწოლას.







