„Xygeni“ kenkėjiško kodo santrauka 88

„Xygeni“ kenkėjiško kodo santrauka 88

Kaip ir kiekvieną savaitę, mūsų kenkėjiškų programų aptikimo sistemos nuskaito tūkstančius naujų ir atnaujintų paketų viešuosiuose registruose. We confirmed 81 malicious package versions between September 11 and 17, 2026, with a single npm package flooding the registry with 39 versions in under half an hour, a plugin-naming campaign that is still uploading as this goes out, and four separate actors reaching for the same version-inflation trick.

@nimbusedge/auth accounts for 39 of this week’s confirmations on its own, published as versions in the 19999.x range within roughly twenty minutes on September 11. Publishing that many versions that fast is not an attempt at credibility, it is an attempt to sit above whatever an internal package resolves to. Separately, 21 packages sharing the meeb322k bei meeb suffixes appeared across three consecutive days, almost all of them following Strapi plugin naming conventions and pinned to the same 3.6.8 version. The uploads continued through September 17, which makes this an active campaign rather than a batch.

Taip pat verta paminėti: concierge-sdk at 99.99.99 and 99.99.100, @traktis/core bei @traktis/environment at 99.99.2, and three etoro- prefixed packages at 99.0.2 all reached for inflated version numbers in the same week, alongside the nimbusedge case. Two packages targeted n8n node naming (n8n-nodes-sysdiag2, n8n-nodes-buildcheck) Ir darkglitch on PyPI shipped 1.4.4 and 1.4.5 back-to-back.

Ši savaitės apžvalga yra mūsų nuolatinės veiklos dalis. Kenkėjiško kodo santrauka, kur mes tikriname naujas grėsmes, kad padėtume „DevSecOps“ komandoms apsaugoti savo pipelines prieš atsirandant žalai.

ekosistemaPaketasData
pypilucy-python-script-2030:0.1.1Rugsėjis 11, 2026
pypilucy-python-script-2030:0.1.2Rugsėjis 11, 2026
npmcr-bot-common:1.0.0Rugsėjis 11, 2026
npm@nimbusedge/auth:19999.x (39 versions)Rugsėjis 11, 2026
npmetoro-cashout:99.0.2Rugsėjis 11, 2026
npmetoro-analytics:99.0.2Rugsėjis 11, 2026
npmetoro-aggregator:99.0.2Rugsėjis 11, 2026
pypiaitextkit-py:0.1.1Rugsėjis 11, 2026
npmnoblox-asset.js:7.4.0Rugsėjis 12, 2026
npmconcierge-sdk:99.99.99Rugsėjis 13, 2026
npmconcierge-sdk:99.99.100Rugsėjis 13, 2026
npmdilxztech:1.0.9Rugsėjis 14, 2026
pypidarkglitch:1.4.4Rugsėjis 15, 2026
pypidarkglitch:1.4.5Rugsėjis 15, 2026
npmos-info-meeb322k:1.0.0Rugsėjis 15, 2026
npmfs-pwn-meeb322k:1.0.0Rugsėjis 15, 2026
npmstrapi-plugin-os-info-meeb322k:3.6.8Rugsėjis 15, 2026
npmstrapi-plugin-running-services-meeb322k:3.6.8Rugsėjis 15, 2026
npmfulfillment-cuprum-auth-widget:3.7.2Rugsėjis 15, 2026
npmn8n-nodes-sysdiag2:2.0.2Rugsėjis 15, 2026
npmn8n-nodes-sysdiag2:2.0.0Rugsėjis 15, 2026
npmalkajsdfoiwqeusdflkjsdf:3.7.3Rugsėjis 15, 2026
npmn8n-nodes-buildcheck:1.0.0Rugsėjis 15, 2026
npmstrapi-plugin-rs-meeb322k:3.6.8Rugsėjis 15, 2026
npmstrapi-plugin-revs-meeb322k:3.6.8Rugsėjis 15, 2026
npmstrapi-plugin-revs01-meeb322k:3.6.8Rugsėjis 15, 2026
npmstrapi-plugin-revs02-meeb322k:3.6.8Rugsėjis 15, 2026
npmstrapi-plugin-revsh-meeb322k:3.6.8Rugsėjis 15, 2026
npmstrapi-plugin-tryccresh-meeb:3.6.8Rugsėjis 16, 2026
npmstrapi-plugin-proccresh-meeb:3.6.8Rugsėjis 16, 2026
npmstrapi-plugin-yayccresh-meeb:3.6.8Rugsėjis 16, 2026
npmstrapi-plugin-yesccresh-meeb:3.6.8Rugsėjis 16, 2026
npmstrapi-plugin-uicc-meeb:3.6.8Rugsėjis 16, 2026
npmcsa-mfa:1.1.15Rugsėjis 16, 2026
npmstrapi-plugin-pencc-meeb:3.6.8Rugsėjis 16, 2026
npmstrapi-plugin-ccsuc-meeb:3.6.8Rugsėjis 16, 2026
npmstrapi-plugin-ccrec-meeb:3.6.8Rugsėjis 17, 2026
npmstrapi-plugin-cccon-meeb:3.6.8Rugsėjis 17, 2026
npmstrapi-plugin-conresh-meeb:3.6.8Rugsėjis 17, 2026
npmstrapi-plugin-ccip-meeb:3.6.8Rugsėjis 17, 2026
npmstrapi-plugin-ccrev-meeb:3.6.8Rugsėjis 17, 2026
npm@traktis/core:99.99.2Rugsėjis 17, 2026
npm@traktis/environment:99.99.2Rugsėjis 17, 2026

Four Actors, One Trick: 81 Malicious Package Versions This Week

This week’s digest shows volume being used as a weapon: a single package published 39 times in twenty minutes, a plugin-naming campaign still uploading on the day we published, and four separate actors reaching for the same inflated version numbers.

@nimbusedge/auth shipped 39 versions in the 19999.x range in under half an hour, which is not an attempt to look legitimate but an attempt to sit above whatever an internal package resolves to. The meeb cluster took the opposite approach: 21 packages following Strapi plugin naming conventions, all pinned to 3.6.8, drip-fed across three consecutive days and still going. And concierge-sdk, @traktis/core, trys etoro- packages and nimbusedge all used the same inflated-version tactic in the same week, which tells you it is working often enough to be worth repeating.

„Xygeni“ ankstyvas įspėjimas apie kenkėjiškas programas monitors npm, PyPI, Maven, Composer, OpenVSX, and other registries in real time, flagging threats at publication, before they reach a build and before an AI agent installs them autonomously. When one actor can publish 39 versions in twenty minutes, detection that waits for a signature is not late by days, it is late by the entire attack.

Ksigenis Open Source Security Platforma suteikia „DevSecOps“ komandoms galimybę realiuoju laiku aptikti ir nustatyti prioritetus, kad būtų galima išvengti koordinuoto tiekimo grandinės spaudimo.

sca-tools-software-composition-analyses-tools
Prioritetizuoti, pašalinti ir apsaugoti savo programinės įrangos rizikas
Gaukite nemokamą paskyrą.
Nebūtina kreditinės kortelės.

Apsaugokite savo programinės įrangos kūrimą ir tiekimą

su „Xygeni“ produktų rinkiniu