Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 114 malicious packages between August 7 and August 14, 2026, led by an npm package cluster openly branded after a real dark-LLM attacker tool, a dependency-confusion wave targeting DeFi and Web3 protocol libraries, and a large-scale brand-squatting campaign against a Brazilian fintech provider.
De meest opvallende vondst: wormgpt-cli Op npm werden op 7 augustus negen versies in snel tempo gepubliceerd, samen met een bijbehorend pakket. gpt-terminal-cli, gepubliceerd op dezelfde dag. De naam is een directe verwijzing naar WormGPT, een echte dark-LLM-tool die aan cybercriminelen wordt verkocht voor phishing en het genereren van malware. Dit suggereert dat het pakket profiteert van de naamsbekendheid van een daadwerkelijke aanvalstool in plaats van zich te verschuilen achter een neutrale naam.
A separate cluster targeted decentralized finance infrastructure directly: ten package names on npm impersonating real DeFi protocol and standards libraries (ethereum-vault-connector, boring-vault, camelot-ammv2-core, camelot-ammv2-periphery, @aerodrome-finance/contracts, @aerodrome-finance/slipstream, permit2, @openzeppelin-4/contracts, @openzeppelin-5/contracts, passkeys-react), sixteen confirmed versions in total, published within hours of each other on August 11. It’s a dependency-confusion play aimed squarely at developers building on Camelot, Aerodrome Finance, and OpenZeppelin’s standard contracten.
The largest single cluster this week impersonated Alelo, a Brazilian corporate benefits and payment card provider: ten distinct package names (alelo-core, alelo-api, alelo-client, alelo-utils, alelo-auth, alelo-sdk, alelo-services, alelo-common, alelo-payment, meualelo), most published in two or three versions, for twenty-one confirmed packages on August 14 alone. Alongside it, a separate scoped-namespace campaign published twenty-one lookalike n8n-nodes-utils-helper-* packages across three npm scopes (@years17, @years18, @years20) between August 13 and 14, a pattern consistent with automated squatting against the n8n automation platform’s node ecosystem rather than a single hand-crafted attack.
Two Maven packages published under io.github.davidtimur/c2-lab on August 7 are worth flagging on name alone. C2 is short for command-and-control, and a package advertising that function in its own name is either remarkably careless or testing how fast detection catches up. For more on Maven-specific supply chain risk, see our analysis of JavaCDoor, a compile-time backdoor we uncovered in the Maven ecosystem.
Deze wekelijkse momentopname maakt deel uit van onze doorlopende Schadelijke codeoverzichtwaar we nieuwe bedreigingen valideren en bruikbare informatie verstrekken om DevSecOps-teams te helpen hun systemen te beschermen. pipelines voordat er schade optreedt.
When a Name Gives It Away: 114 Malicious Packages This Week
This week’s digest shows attackers leaning on brand recognition rather than hiding from it. wormgpt-cli went from zero to nine versions on npm in a single day, brazenly named after a real dark-LLM tool sold to cybercriminals, alongside a companion package, gpt-terminal-cli, published the same day. Two Maven packages went further still, publishing openly under the name c2-lab, command-and-control spelled out in the package name itself.
Volume told its own story elsewhere. A ten-package cluster impersonating DeFi protocol libraries (ethereum-vault-connector, boring-vault, camelot-ammv2-core, and others) landed sixteen confirmed versions within hours of each other on August 11, a synchronized drop aimed at developers pulling in what look like standard contracts from Camelot, Aerodrome Finance, and OpenZeppelin. Days later, a ten-name cluster impersonating Alelo, a Brazilian corporate benefits provider, produced twenty-one confirmed packages in a single day, while a parallel campaign squatted twenty-one lookalike n8n-nodes-utils-helper-* names across three separate npm scopes, a pattern that points to automated squatting infrastructure rather than one attacker working by hand.
Vroege malwarewaarschuwing van Xygeni monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When a scoped namespace produces twenty-one lookalike packages in two days, or a Maven artifact ships with its intent in the name, detection that runs after the fact is already too late.
Xygeni's Open Source Security Het platform biedt DevSecOps-teams de realtime detectie en prioritering die nodig zijn om de druk van gecoördineerde toeleveringsketens voor te blijven, zodat uw pipelineZorg voor een schone omgeving zonder je teams te vertragen.





