Kaip ir kiekvieną savaitę, mūsų kenkėjiškų programų aptikimo sistemos nuskaito tūkstančius naujų ir atnaujintų paketų viešuosiuose registruose. We confirmed 81 malicious package versions between September 11 and 17, 2026, with a single npm package flooding the registry with 39 versions in under half an hour, a plugin-naming campaign that is still uploading as this goes out, and four separate actors reaching for the same version-inflation trick.
@nimbusedge/auth accounts for 39 of this week’s confirmations on its own, published as versions in the 19999.x range within roughly twenty minutes on September 11. Publishing that many versions that fast is not an attempt at credibility, it is an attempt to sit above whatever an internal package resolves to. Separately, 21 packages sharing the meeb322k bei meeb suffixes appeared across three consecutive days, almost all of them following Strapi plugin naming conventions and pinned to the same 3.6.8 version. The uploads continued through September 17, which makes this an active campaign rather than a batch.
Taip pat verta paminėti: concierge-sdk at 99.99.99 and 99.99.100, @traktis/core bei @traktis/environment at 99.99.2, and three etoro- prefixed packages at 99.0.2 all reached for inflated version numbers in the same week, alongside the nimbusedge case. Two packages targeted n8n node naming (n8n-nodes-sysdiag2, n8n-nodes-buildcheck) Ir darkglitch on PyPI shipped 1.4.4 and 1.4.5 back-to-back.
Ši savaitės apžvalga yra mūsų nuolatinės veiklos dalis. Kenkėjiško kodo santrauka, kur mes tikriname naujas grėsmes, kad padėtume „DevSecOps“ komandoms apsaugoti savo pipelines prieš atsirandant žalai.
Four Actors, One Trick: 81 Malicious Package Versions This Week
This week’s digest shows volume being used as a weapon: a single package published 39 times in twenty minutes, a plugin-naming campaign still uploading on the day we published, and four separate actors reaching for the same inflated version numbers.
@nimbusedge/auth shipped 39 versions in the 19999.x range in under half an hour, which is not an attempt to look legitimate but an attempt to sit above whatever an internal package resolves to. The meeb cluster took the opposite approach: 21 packages following Strapi plugin naming conventions, all pinned to 3.6.8, drip-fed across three consecutive days and still going. And concierge-sdk, @traktis/core, trys etoro- packages and nimbusedge all used the same inflated-version tactic in the same week, which tells you it is working often enough to be worth repeating.
„Xygeni“ ankstyvas įspėjimas apie kenkėjiškas programas monitors npm, PyPI, Maven, Composer, OpenVSX, and other registries in real time, flagging threats at publication, before they reach a build and before an AI agent installs them autonomously. When one actor can publish 39 versions in twenty minutes, detection that waits for a signature is not late by days, it is late by the entire attack.
Ksigenis Open Source Security Platforma suteikia „DevSecOps“ komandoms galimybę realiuoju laiku aptikti ir nustatyti prioritetus, kad būtų galima išvengti koordinuoto tiekimo grandinės spaudimo.







