„xygeni“ kenkėjiško kodo santrauka 87

„Xygeni“ kenkėjiško kodo santrauka 87

As every week, our malware detection systems scan thousands of new and updated packages across public registries. We confirmed 13 malicious packages between September 7 and 11, 2026, with the Baileys impersonation campaign still running, the first Composer cluster we have flagged, and two more cases of the version-inflation pattern used in dependency confusion.

cloud-baileys shipped two more versions (1.1.39 and 1.1.40), extending a campaign that has now produced new identities for several weeks straight. Composer appeared for the first time with three PHP packages published under form-handling names (slimfit/slimbase, slimfit/formbase, gcform/formhelper), a reminder that these operations follow developers rather than ecosystems. @umschool/platform was published at 999.0.0, the inflated version number typical of dependency confusion, and twilio-hackerone-poc-b8f21a shipped two versions under a name that reads as a proof of concept against a specific vendor’s internal package namespace.

Taip pat verta paminėti: darkglitch on PyPI shipped 1.4.4 and 1.4.5 within minutes of each other, and the registry itself confirmed syswatch and samaki after our earlier detection.

Ši savaitės apžvalga yra mūsų nuolatinės veiklos dalis. Kenkėjiško kodo santrauka, kur mes tikriname naujas grėsmes, kad padėtume „DevSecOps“ komandoms apsaugoti savo pipelines prieš atsirandant žalai.

ekosistemaPaketasData
pypisistemos stebėjimas: 1.0.0Rugsėjis 07, 2026
pypisamaki:0.4.9Rugsėjis 07, 2026
sukomponuotislimfit/slimbase:2.0Rugsėjis 07, 2026
sukomponuotislimfit/formbase:1.2Rugsėjis 07, 2026
sukomponuotigcform/formhelper:1.2Rugsėjis 07, 2026
npmdebesies-baileys:1.1.39Rugsėjis 07, 2026
npmalloy-graphql:1.0.1Rugsėjis 08, 2026
npm@umschool/platform:999.0.0Rugsėjis 10, 2026
npmtwilio-hackerone-poc-b8f21a:1.0.0Rugsėjis 10, 2026
npmtwilio-hackerone-poc-b8f21a:1.0.1Rugsėjis 10, 2026
npmdebesies-baileys:1.1.40Rugsėjis 11, 2026
pypidarkglitch:1.4.4Rugsėjis 11, 2026
pypidarkglitch:1.4.5Rugsėjis 11, 2026

Three Ecosystems, One Pattern: 13 Malicious Packages This Week

This week’s digest shows familiar operations widening their footprint: a campaign still publishing after weeks of detection, the first Composer cluster to appear here, and two packages using an inflated version number to win a resolution race.

cloud-baileys shipped 1.1.39 and 1.1.40 within days, consistent with an attacker who treats takedowns as a cost of operating rather than a reason to stop. Composer appeared for the first time with three PHP packages under form-handling names (slimfit/slimbase, slimfit/formbase, gcform/formhelper), a reminder that these operations follow developers, not ecosystems. And @umschool/platform was published at 999.0.0, the inflated version that exists for one reason: to outrank the internal package your teams actually wrote.

„Xygeni“ ankstyvas įspėjimas apie kenkėjiškas programas monitors npm, PyPI, Maven, Composer, OpenVSX, and other registries in real time, flagging threats at publication, before they reach a build and before an AI agent installs them autonomously. When a campaign resurfaces week after week, detection that only checks once is already behind.

Ksigenis Open Source Security platform gives DevSecOps teams the real-time detection and prioritization to stay ahead of coordinated supply chain pressure.

sca-tools-software-composition-analyses-tools
Prioritetizuoti, pašalinti ir apsaugoti savo programinės įrangos rizikas
Gaukite nemokamą paskyrą.
Nebūtina kreditinės kortelės.

Apsaugokite savo programinės įrangos kūrimą ir tiekimą

su „Xygeni“ produktų rinkiniu