בייזוויליקע קאָד דיידזשעסט יוני

בייזוויליקע קאָד דיידזשעסט מאָנטלעך איבערבליק: יולי

Welcome to the July edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed over 780 malicious packages across npm, PyPI, and OpenVSX (the VS Code extension marketplace), tracked across five weekly digests.

July was defined by three converging trends: sustained, high-volume version-flooding campaigns designed to outlast takedowns; a sharp escalation in attacks targeting AI tooling, MCP servers, and agentic workflows; and coordinated dependency-confusion campaigns against both enterprise namespaces and crypto/DeFi ecosystems.

צווישן די מערסט באַמערקבאַרע קאַמפּיינז דאָקומענטירט דעם חודש:

  • bingo-ai on PyPI resurfaced twice, flooding the registry with well over 150 versions across two bursts (July 13 and July 21), confirming this is an ongoing operation, not a one-off.
  • zevairouter became July’s largest single-package campaign: over 65 versions across npm, published continuously from July 25–28.
  • gcli-control, the Windows RAT we profiled in detail that routes its C2 through npoint.io, escalated from version 0.1.0 to 0.13.0 across three separate weeks.
  • @szc-ft/mcp-szcd-client, the package behind סקילליק, our writeup on a credential decryptor delivered through a bundled MCP skill, was confirmed July 2.
  • The week of July 7 brought the month’s heaviest AI-tooling targeting: mcp-server-pg, anthropic-toolkit, openai-agents-helpers, ollama-helpers, און @langgraphjs/toolkit, impersonating MCP, Anthropic, OpenAI, Ollama, and LangGraph.
  • A 17-package PayPal impersonation cluster hit npm July 27, all at version 28.0.0 within minutes.
  • @wagni_bot, roughly 60 npm packages impersonating crypto wallet SDKs (Ethereum, Solana, Binance, and more), all published in a single day, July 10.
  • Over a dozen fake VS Code extensions surfaced on OpenVSX, confirming attackers are expanding beyond package registries into the IDE itself.

The defining pattern of July: attacks increasingly target the AI agents and automated tooling that install packages with no human reviewer in the loop, at a publishing velocity built to outrun manual review.

Below is a summary of what we found. You can see all five weeks’ data disclosed in full detail at the Malicious Code Digest index.

וואָך 5: איבער 180 פּעקלעך אַנטדעקט

יקאָוסיסטאַם פּעקל באשטעטיקט
npm@cryptosrvc/shift-sdk-v4:1.0.77יולי קסנומקס, קסנומקס
אָופּענװסקסcesium/gltf-vscode:0.0.1יולי קסנומקס, קסנומקס
pypigcli-קאנטראל:0.13.0יולי קסנומקס, קסנומקס
vscodeairtune:1.0.0יולי קסנומקס, קסנומקס
npmzevairouter:1.0.109יולי קסנומקס, קסנומקס
npmidentityauthorizationserv:28.0.0יולי קסנומקס, קסנומקס
npmmerchantprefsservice-paypal:28.0.0יולי קסנומקס, קסנומקס
npmxo-member-components:28.0.0יולי קסנומקס, קסנומקס
אָופּענװסקסtechnosophos/vscode-helm:0.0.1יולי קסנומקס, קסנומקס
אָופּענװסקסbastienboutonnet/vscode-dbt:0.0.1יולי קסנומקס, קסנומקס
npmmarkscan:1.0.0יולי קסנומקס, קסנומקס
npmiphouse:1.0.0יולי קסנומקס, קסנומקס
npmakrai-report-new:1.0.0יולי קסנומקס, קסנומקס
pypivtranalytic:8.0.0יולי קסנומקס, קסנומקס
npmgreatcall-customers-commandapi:99.0.0יולי קסנומקס, קסנומקס
npmblots:2.1.1יולי קסנומקס, קסנומקס
npm@ey-china/ey-assistant:1.0.1יולי קסנומקס, קסנומקס
npmflydev:0.0.1יולי קסנומקס, קסנומקס
npm@qtestorgz/sdk:1.0.0יולי קסנומקס, קסנומקס

וואָך 4: איבער 165 פּעקלעך אַנטדעקט

יקאָוסיסטאַם פּעקל באשטעטיקט
npmדזשאַוואַס-קריפּטאָ:2.0.4יולי קסנומקס, קסנומקס
npmקלאָווער-קאָודלאַב-רימאָוט-פּיי-וואָלקן:99.9.9יולי קסנומקס, קסנומקס
npmנאכפאלג-פינאַנץ: 99.0.0יולי קסנומקס, קסנומקס
npmטוויליאָ-סערווערלעסס: 99.99.99יולי קסנומקס, קסנומקס
npmסופּליי-האַב: 1.0.1יולי קסנומקס, קסנומקס
npm@offa/offa-uwk:999.0.0יולי קסנומקס, קסנומקס
npmדאַטע-פֿאָרמאַט-יוטילס-xz:1.0.1יולי קסנומקס, קסנומקס
pypiבינגאָ-איי:6.2.241יולי קסנומקס, קסנומקס
npm@bpa-internal/bpa-utils:99.99.99יולי קסנומקס, קסנומקס
npmn8n-נאָודז-פּון:1.0.1יולי קסנומקס, קסנומקס
pypigcli-קאנטראל:0.1.0יולי קסנומקס, קסנומקס
npmיוניסוואַפּ-סדק-וו4:1.0.0יולי קסנומקס, קסנומקס
npmוואַגמי-רעאַקט: 1.0.0יולי קסנומקס, קסנומקס
npmעטערס-זיכער: 1.0.0יולי קסנומקס, קסנומקס
pypigcli-קאנטראל:0.12.0יולי קסנומקס, קסנומקס
npmדאַטעפֿמט-פּראָ: 1.0.1יולי קסנומקס, קסנומקס
npm@daylightqc/date-fmt-lite:1.0.0יולי קסנומקס, קסנומקס

וואָך 3: איבער 145 פּעקלעך אַנטדעקט

יקאָוסיסטאַם פּעקל באשטעטיקט
npmענוו-פאַסט: 1.0.0יולי קסנומקס, קסנומקס
pypiלבנה-uv:0.0.25יולי קסנומקס, קסנומקס
npmגוגל-קאדזשא-באוער:1000.800.20יולי קסנומקס, קסנומקס
npmvuln-package:99.9.14יולי קסנומקס, קסנומקס
pypiבינגאָ-איי:6.2.109יולי קסנומקס, קסנומקס
npmבאַג עקספּלאָיט: 99.9.9יולי קסנומקס, קסנומקס
npmאמדאקס-קאָר-פּעקל: 11.11.11יולי קסנומקס, קסנומקס
npmאַרב-קיט: 1.0.0יולי קסנומקס, קסנומקס
npmסאָלאַנאַ-שליסל-יוטילס:1.0.0יולי קסנומקס, קסנומקס
npmaxios-test-one:1.18.9יולי קסנומקס, קסנומקס
pypiפּלאַנדזשער העקער: 2.0.1יולי קסנומקס, קסנומקס
pypiלאָג-גורו: 0.7.8יולי קסנומקס, קסנומקס
pypiפּילאָגאָראַ: 0.7.8יולי קסנומקס, קסנומקס
npm@across-toolkit/eslint-config:99.0.0יולי קסנומקס, קסנומקס
npmגילטיקע פּילאָט-mcp:1.4.0יולי קסנומקס, קסנומקס
npmניקסאָראַ: 26.7.17יולי קסנומקס, קסנומקס

וואָך 2: איבער 200 פּעקלעך אַנטדעקט

יקאָוסיסטאַם פּעקל באשטעטיקט
pypiפּראָקווייער:5.2.7יולי קסנומקס, קסנומקס
npmנעאָן-טערמינאַל: 0.3.0יולי קסנומקס, קסנומקס
npmנאָלימיט-אַגענט: 1.0.336יולי קסנומקס, קסנומקס
vscodeאַנדרויד-שטיצע-פֿרэйמווערק-קעגן:0.0.1יולי קסנומקס, קסנומקס
npmmcp-סערווער-pg:1.0.0יולי קסנומקס, קסנומקס
npmאַנטראָפּישע-טוילקיט: 1.3.1יולי קסנומקס, קסנומקס
npmאָפּענאַי-אַגענטן-העלפערס: 1.3.3יולי קסנומקס, קסנומקס
npmדיבאַגקלי:4.4.1יולי קסנומקס, קסנומקס
npmהעלא244א:1.0.38יולי קסנומקס, קסנומקס
npmדונער-ראָני: 99.9.9יולי קסנומקס, קסנומקס
pypiלבנה-uv:0.0.5יולי קסנומקס, קסנומקס
npmes6-קאָדיפֿיציר:2.0.0יולי קסנומקס, קסנומקס
npmn8n-נאָודז-מקפּוטילס:0.1.4יולי קסנומקס, קסנומקס
npm@wagni_bot/hyperliquid-sdk:1.0.0יולי קסנומקס, קסנומקס
npm@wagni_bot/metemask-sdk:1.0.0יולי קסנומקס, קסנומקס
npm@wagni_bot/pumpfun-sdk:1.0.0יולי קסנומקס, קסנומקס
npm@wagni_bot/binance-sdk:1.0.0יולי קסנומקס, קסנומקס
npm@wagni_bot/ethereum-wallet:1.0.0יולי קסנומקס, קסנומקס
npmטעסטינג-d3do:99.9.9יולי קסנומקס, קסנומקס
npmקליענט-קוקיז-אגענט: 99.9.6יולי קסנומקס, קסנומקס

וואָך 1: איבער 90 פּעקלעך אַנטדעקט

יקאָוסיסטאַם פּעקל באשטעטיקט
npmפארשאלטענע-מאָדולן: 999.1.2יולי קסנומקס, קסנומקס
npm@szc-ft/mcp-szcd-קליענט:0.39.0יולי קסנומקס, קסנומקס
npmפּפּ-רעאַקט-וו5:30.0.2יולי קסנומקס, קסנומקס
npmקאנסטעלעי:0.5.1יולי קסנומקס, קסנומקס
npmדאַטע-fns-לייט:1.0.9יולי קסנומקס, קסנומקס
npm@easypayment/medusa-paypal:0.7.6יולי קסנומקס, קסנומקס
npmדל-פּפּ-לאַטם:80.4.2יולי קסנומקס, קסנומקס
npm@sudoughnym/enviro-demo:99.99.99יולי קסנומקס, קסנומקס
npmנאָלימיט-אַגענט: 1.0.316יולי קסנומקס, קסנומקס
npmפארשאלטענע-עקטא-ד3אב00:1.0.0יולי קסנומקס, קסנומקס
npm@checkrhq/adjudication-api-client:0.0.2יולי קסנומקס, קסנומקס

From Version Storms to AI Impersonation: What July’s Supply Chain Attacks Reveal

The campaigns above aren’t edge cases, they’re the baseline now. Version-flooding storms, coordinated impersonation drops, and AI-tooling lookalikes are hitting real teams in real SDLCs every week, often with no human in the loop between publication and install.

קסיגעני'ס מאַלוואַרע דיטעקשאַן און supply chain security platform gives organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. Coverage spans npm, PyPI, OpenVSX, and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.

יעדע געפינס ווערט אויטאמאטיש פּריאָריטיזירט לויט עקספּלויטאַביליטעט, דערגרייכבאַרקייט, און געשעפטלעכע השפּעה, אַזוי אַז אייער מאַנשאַפֿט קאָנצענטרירט זיך אויף וואָס דאַרף טאַקע פֿאַרריכטן ווערן, נישט אויף ראַש.

אויספאָרשן יעדן בייזוויליקן פּעקל און קאַמפּיין וואַלידירט דורך די Xygeni זיכערהייט מאַנשאַפֿט אין די בייזוויליקע קאָד דיידזשעסט.

בלייבט זיכער. בלייבט שנעל. בלייבט אין קאנטראל מיט קסיגעני.

סקאַ-טולס-סאָפֿטווער-קאָמפּאָזיציע-אַנאַליז-טולס
פּריאָריטיזירן, פאַרריכטן און זיכערן אייערע ווייכווארג ריזיקעס
באַקומען דיין פריי חשבון.
קיין קרעדיט קאַרטל פארלאנגט.

זיכערן אייער ווייכווארג אנטוויקלונג און ליפערונג

מיט Xygeni פּראָדוקט סוויט