خراب ڪوڊ ڊائجسٽ 84

زائيگيني خراب ڪوڊ ڊائجسٽ 84

Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 34 malicious packages between August 15 and August 20, 2026, led by a sustained impersonation campaign against Baileys, a popular open-source WhatsApp Web API library, a cluster of Twilio/HackerOne-branded probe packages, and a set of unrelated-looking npm packages sharing an identical, unusually high version number.

The Baileys impersonation ran the longest: four separate package names (@mrlegendbot/baileys, cloud-baileys, @vanzxy/baileys, ourin-baileys) confirmed across six days, with cloud-baileys alone republished four times between August 15 and 20 under climbing version numbers, a pattern consistent with an attacker iterating past detection rather than a one-off upload.

A separate cluster on August 15 published packages referencing Twilio and HackerOne (twilio-hackerone-poc-afe6937c, five versions in one day, plus tw-pkgprobe-7731 ۽ hunterone-build-probe-9210), naming conventions typically associated with bug-bounty or dependency-confusion probing rather than a disguised payload.

Also worth flagging: pump-segments-sdk, carbon-monorepo، ۽ pump-fun-skills, three otherwise unrelated package names all published at version 20.1.1 on August 19, an unusual shared version number across supposedly independent projects that suggests a single actor behind all three.

هي هفتيوار تصوير اسان جي جاري جو حصو آهي خراب ڪوڊ ڊائجسٽ, where we validate new threats to help DevSecOps teams protect their pipelineنقصان ٿيڻ کان اڳ.

ماحولياتي نظام پئڪيج تاريخ
نيٺhunterone-build-probe-9210:1.0.0آگسٽ 15، 2026
نيٺtwilio-hackerone-poc-afe6937c:1.0.0آگسٽ 15، 2026
نيٺtw-pkgprobe-7731:1.0.0آگسٽ 15، 2026
نيٺtwilio-hackerone-poc-afe6937c:1.0.1آگسٽ 15، 2026
نيٺtwilio-hackerone-poc-afe6937c:1.0.2آگسٽ 15، 2026
نيٺtwilio-hackerone-poc-afe6937c:1.0.3آگسٽ 15، 2026
نيٺtwilio-hackerone-poc-afe6937c:1.0.4آگسٽ 15، 2026
نيٺ@mrlegendbot/baileys:1.2.4آگسٽ 15، 2026
نيٺcloud-baileys:1.1.3آگسٽ 15، 2026
نيٺ@vanzxy/baileys:1.4.2آگسٽ 16، 2026
نيٺourin-baileys:9.0.11آگسٽ 16، 2026
نيٺاکيون: 4.0.1آگسٽ 16، 2026
نيٺcloud-baileys:1.1.33آگسٽ 16، 2026
نيٺmoidev:1.0.0آگسٽ 16، 2026
نيٺ@wangjiezhong/dsh-memory:0.1.1آگسٽ 17، 2026
نيٺ@wangjiezhong/dsh-memory:0.1.2آگسٽ 17، 2026
نيٺ@wangjiezhong/dsh-memory:0.1.3آگسٽ 17، 2026
نيٺ@wangjiezhong/dsh-memory:0.1.4آگسٽ 17، 2026
نيٺmoidevx:1.0.0آگسٽ 17، 2026
نيٺdxr-dos:0.1.2آگسٽ 17، 2026
نيٺdxr-dos:0.1.1آگسٽ 17، 2026
نيٺdxr-dos:0.1.3آگسٽ 17، 2026
نيٺcloud-baileys:1.1.34آگسٽ 18، 2026
پائيپيreqcrypt:0.1.0آگسٽ 18، 2026
نيٺdxrs-dos:0.1.3آگسٽ 18، 2026
نيٺprism-registry:1.0.1آگسٽ 18، 2026
نيٺoptimizely-starter-kit-for-fastly-compute:1.0.1آگسٽ 18، 2026
نيٺ@mohamed_nowisar/canary-confirm-token3:0.0.1آگسٽ 18، 2026
نيٺ@mohamed_nowisar/depconf-canary-test:0.0.1آگسٽ 18، 2026
نيٺ@mohamed_nowisar/token3-check:0.0.1آگسٽ 18، 2026
نيٺpump-segments-sdk:20.1.1آگسٽ 19، 2026
نيٺcarbon-monorepo:20.1.1آگسٽ 19، 2026
نيٺpump-fun-skills:20.1.1آگسٽ 19، 2026
نيٺcloud-baileys:1.1.35آگسٽ 20، 2026

When Iteration Beats Detection: 34 Malicious Packages This Week

This week’s digest shows attackers leaning on persistence rather than a single lucky upload. The cloud-baileys impersonation of the popular WhatsApp Web API library was republished four separate times between August 15 and 20 under climbing version numbers, joined by three other lookalike names (@mrlegendbot/baileys, @vanzxy/baileys, ourin-baileys), a sustained campaign rather than a one-off attempt.

Naming conventions gave other clusters away just as fast. A group of packages branded around Twilio and HackerOne, including twilio-hackerone-poc-afe6937c published in five versions in a single day, alongside tw-pkgprobe-7731 ۽ hunterone-build-probe-9210, used naming patterns typically associated with bug-bounty or dependency-confusion probing. Elsewhere, three unrelated package names (pump-segments-sdk, carbon-monorepo, pump-fun-skills) all shipped under the identical version number 20.1.1 on the same day, an unusual coincidence that points to one actor operating behind all three.

زائيگيني جي شروعاتي مالويئر وارننگ monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When the same package name resurfaces four times in six days under a new version each time, detection that only checks once is already behind.

زائيگيني جو Open Source Security پليٽ فارم DevSecOps ٽيمن کي حقيقي وقت جي سڃاڻپ ۽ ترجيح ڏئي ٿو جيڪو هم آهنگ سپلائي چين پريشر کان اڳتي رهڻ لاءِ گهربل آهي، تنهن ڪري توهان جو pipelineپنهنجي ٽيمن کي سست ڪرڻ کان سواءِ صاف رهو.

اسڪا-ٽولز-سافٽ ويئر-ڪمپوزيشن-تجزيو-ٽولز
پنهنجي سافٽ ويئر خطرن کي ترجيح ڏيو، درست ڪريو، ۽ محفوظ ڪريو
پنهنجو مفت اڪائونٽ حاصل ڪريو.
ڪنهن به ڪريڊٽ ڪارڊ جي ضرورت نه آهي.

پنهنجي سافٽ ويئر ڊولپمينٽ ۽ پهچائڻ کي محفوظ بڻايو

زائيگيني پراڊڪٽ سوٽ سان