Welcome to the July edition of the Xygeni Malicious Code Digest. This month, our security research team confirmed over 780 malicious packages across npm, PyPI, and OpenVSX (the VS Code extension marketplace), tracked across five weekly digests.
July was defined by three converging trends: sustained, high-volume version-flooding campaigns designed to outlast takedowns; a sharp escalation in attacks targeting AI tooling, MCP servers, and agentic workflows; and coordinated dependency-confusion campaigns against both enterprise namespaces and crypto/DeFi ecosystems.
צווישן די מערסט באַמערקבאַרע קאַמפּיינז דאָקומענטירט דעם חודש:
bingo-aion PyPI resurfaced twice, flooding the registry with well over 150 versions across two bursts (July 13 and July 21), confirming this is an ongoing operation, not a one-off.zevairouterbecame July’s largest single-package campaign: over 65 versions across npm, published continuously from July 25–28.gcli-control, the Windows RAT we profiled in detail that routes its C2 through npoint.io, escalated from version 0.1.0 to 0.13.0 across three separate weeks.@szc-ft/mcp-szcd-client, the package behind סקילליק, our writeup on a credential decryptor delivered through a bundled MCP skill, was confirmed July 2.- The week of July 7 brought the month’s heaviest AI-tooling targeting:
mcp-server-pg,anthropic-toolkit,openai-agents-helpers,ollama-helpers, און@langgraphjs/toolkit, impersonating MCP, Anthropic, OpenAI, Ollama, and LangGraph. - A 17-package PayPal impersonation cluster hit npm July 27, all at version 28.0.0 within minutes.
@wagni_bot, roughly 60 npm packages impersonating crypto wallet SDKs (Ethereum, Solana, Binance, and more), all published in a single day, July 10.- Over a dozen fake VS Code extensions surfaced on OpenVSX, confirming attackers are expanding beyond package registries into the IDE itself.
The defining pattern of July: attacks increasingly target the AI agents and automated tooling that install packages with no human reviewer in the loop, at a publishing velocity built to outrun manual review.
Below is a summary of what we found. You can see all five weeks’ data disclosed in full detail at the Malicious Code Digest index.
וואָך 5: איבער 180 פּעקלעך אַנטדעקט
| יקאָוסיסטאַם | פּעקל | באשטעטיקט |
|---|---|---|
| npm | @cryptosrvc/shift-sdk-v4:1.0.77 | יולי קסנומקס, קסנומקס |
| אָופּענװסקס | cesium/gltf-vscode:0.0.1 | יולי קסנומקס, קסנומקס |
| pypi | gcli-קאנטראל:0.13.0 | יולי קסנומקס, קסנומקס |
| vscode | airtune:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | zevairouter:1.0.109 | יולי קסנומקס, קסנומקס |
| npm | identityauthorizationserv:28.0.0 | יולי קסנומקס, קסנומקס |
| npm | merchantprefsservice-paypal:28.0.0 | יולי קסנומקס, קסנומקס |
| npm | xo-member-components:28.0.0 | יולי קסנומקס, קסנומקס |
| אָופּענװסקס | technosophos/vscode-helm:0.0.1 | יולי קסנומקס, קסנומקס |
| אָופּענװסקס | bastienboutonnet/vscode-dbt:0.0.1 | יולי קסנומקס, קסנומקס |
| npm | markscan:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | iphouse:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | akrai-report-new:1.0.0 | יולי קסנומקס, קסנומקס |
| pypi | vtranalytic:8.0.0 | יולי קסנומקס, קסנומקס |
| npm | greatcall-customers-commandapi:99.0.0 | יולי קסנומקס, קסנומקס |
| npm | blots:2.1.1 | יולי קסנומקס, קסנומקס |
| npm | @ey-china/ey-assistant:1.0.1 | יולי קסנומקס, קסנומקס |
| npm | flydev:0.0.1 | יולי קסנומקס, קסנומקס |
| npm | @qtestorgz/sdk:1.0.0 | יולי קסנומקס, קסנומקס |
וואָך 4: איבער 165 פּעקלעך אַנטדעקט
| יקאָוסיסטאַם | פּעקל | באשטעטיקט |
|---|---|---|
| npm | דזשאַוואַס-קריפּטאָ:2.0.4 | יולי קסנומקס, קסנומקס |
| npm | קלאָווער-קאָודלאַב-רימאָוט-פּיי-וואָלקן:99.9.9 | יולי קסנומקס, קסנומקס |
| npm | נאכפאלג-פינאַנץ: 99.0.0 | יולי קסנומקס, קסנומקס |
| npm | טוויליאָ-סערווערלעסס: 99.99.99 | יולי קסנומקס, קסנומקס |
| npm | סופּליי-האַב: 1.0.1 | יולי קסנומקס, קסנומקס |
| npm | @offa/offa-uwk:999.0.0 | יולי קסנומקס, קסנומקס |
| npm | דאַטע-פֿאָרמאַט-יוטילס-xz:1.0.1 | יולי קסנומקס, קסנומקס |
| pypi | בינגאָ-איי:6.2.241 | יולי קסנומקס, קסנומקס |
| npm | @bpa-internal/bpa-utils:99.99.99 | יולי קסנומקס, קסנומקס |
| npm | n8n-נאָודז-פּון:1.0.1 | יולי קסנומקס, קסנומקס |
| pypi | gcli-קאנטראל:0.1.0 | יולי קסנומקס, קסנומקס |
| npm | יוניסוואַפּ-סדק-וו4:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | וואַגמי-רעאַקט: 1.0.0 | יולי קסנומקס, קסנומקס |
| npm | עטערס-זיכער: 1.0.0 | יולי קסנומקס, קסנומקס |
| pypi | gcli-קאנטראל:0.12.0 | יולי קסנומקס, קסנומקס |
| npm | דאַטעפֿמט-פּראָ: 1.0.1 | יולי קסנומקס, קסנומקס |
| npm | @daylightqc/date-fmt-lite:1.0.0 | יולי קסנומקס, קסנומקס |
וואָך 3: איבער 145 פּעקלעך אַנטדעקט
| יקאָוסיסטאַם | פּעקל | באשטעטיקט |
|---|---|---|
| npm | ענוו-פאַסט: 1.0.0 | יולי קסנומקס, קסנומקס |
| pypi | לבנה-uv:0.0.25 | יולי קסנומקס, קסנומקס |
| npm | גוגל-קאדזשא-באוער:1000.800.20 | יולי קסנומקס, קסנומקס |
| npm | vuln-package:99.9.14 | יולי קסנומקס, קסנומקס |
| pypi | בינגאָ-איי:6.2.109 | יולי קסנומקס, קסנומקס |
| npm | באַג עקספּלאָיט: 99.9.9 | יולי קסנומקס, קסנומקס |
| npm | אמדאקס-קאָר-פּעקל: 11.11.11 | יולי קסנומקס, קסנומקס |
| npm | אַרב-קיט: 1.0.0 | יולי קסנומקס, קסנומקס |
| npm | סאָלאַנאַ-שליסל-יוטילס:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | axios-test-one:1.18.9 | יולי קסנומקס, קסנומקס |
| pypi | פּלאַנדזשער העקער: 2.0.1 | יולי קסנומקס, קסנומקס |
| pypi | לאָג-גורו: 0.7.8 | יולי קסנומקס, קסנומקס |
| pypi | פּילאָגאָראַ: 0.7.8 | יולי קסנומקס, קסנומקס |
| npm | @across-toolkit/eslint-config:99.0.0 | יולי קסנומקס, קסנומקס |
| npm | גילטיקע פּילאָט-mcp:1.4.0 | יולי קסנומקס, קסנומקס |
| npm | ניקסאָראַ: 26.7.17 | יולי קסנומקס, קסנומקס |
וואָך 2: איבער 200 פּעקלעך אַנטדעקט
| יקאָוסיסטאַם | פּעקל | באשטעטיקט |
|---|---|---|
| pypi | פּראָקווייער:5.2.7 | יולי קסנומקס, קסנומקס |
| npm | נעאָן-טערמינאַל: 0.3.0 | יולי קסנומקס, קסנומקס |
| npm | נאָלימיט-אַגענט: 1.0.336 | יולי קסנומקס, קסנומקס |
| vscode | אַנדרויד-שטיצע-פֿרэйמווערק-קעגן:0.0.1 | יולי קסנומקס, קסנומקס |
| npm | mcp-סערווער-pg:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | אַנטראָפּישע-טוילקיט: 1.3.1 | יולי קסנומקס, קסנומקס |
| npm | אָפּענאַי-אַגענטן-העלפערס: 1.3.3 | יולי קסנומקס, קסנומקס |
| npm | דיבאַגקלי:4.4.1 | יולי קסנומקס, קסנומקס |
| npm | העלא244א:1.0.38 | יולי קסנומקס, קסנומקס |
| npm | דונער-ראָני: 99.9.9 | יולי קסנומקס, קסנומקס |
| pypi | לבנה-uv:0.0.5 | יולי קסנומקס, קסנומקס |
| npm | es6-קאָדיפֿיציר:2.0.0 | יולי קסנומקס, קסנומקס |
| npm | n8n-נאָודז-מקפּוטילס:0.1.4 | יולי קסנומקס, קסנומקס |
| npm | @wagni_bot/hyperliquid-sdk:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | @wagni_bot/metemask-sdk:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | @wagni_bot/pumpfun-sdk:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | @wagni_bot/binance-sdk:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | @wagni_bot/ethereum-wallet:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | טעסטינג-d3do:99.9.9 | יולי קסנומקס, קסנומקס |
| npm | קליענט-קוקיז-אגענט: 99.9.6 | יולי קסנומקס, קסנומקס |
וואָך 1: איבער 90 פּעקלעך אַנטדעקט
| יקאָוסיסטאַם | פּעקל | באשטעטיקט |
|---|---|---|
| npm | פארשאלטענע-מאָדולן: 999.1.2 | יולי קסנומקס, קסנומקס |
| npm | @szc-ft/mcp-szcd-קליענט:0.39.0 | יולי קסנומקס, קסנומקס |
| npm | פּפּ-רעאַקט-וו5:30.0.2 | יולי קסנומקס, קסנומקס |
| npm | קאנסטעלעי:0.5.1 | יולי קסנומקס, קסנומקס |
| npm | דאַטע-fns-לייט:1.0.9 | יולי קסנומקס, קסנומקס |
| npm | @easypayment/medusa-paypal:0.7.6 | יולי קסנומקס, קסנומקס |
| npm | דל-פּפּ-לאַטם:80.4.2 | יולי קסנומקס, קסנומקס |
| npm | @sudoughnym/enviro-demo:99.99.99 | יולי קסנומקס, קסנומקס |
| npm | נאָלימיט-אַגענט: 1.0.316 | יולי קסנומקס, קסנומקס |
| npm | פארשאלטענע-עקטא-ד3אב00:1.0.0 | יולי קסנומקס, קסנומקס |
| npm | @checkrhq/adjudication-api-client:0.0.2 | יולי קסנומקס, קסנומקס |
From Version Storms to AI Impersonation: What July’s Supply Chain Attacks Reveal
The campaigns above aren’t edge cases, they’re the baseline now. Version-flooding storms, coordinated impersonation drops, and AI-tooling lookalikes are hitting real teams in real SDLCs every week, often with no human in the loop between publication and install.
קסיגעני'ס מאַלוואַרע דיטעקשאַן און supply chain security platform gives organizations the visibility to catch malicious dependencies before they execute on a developer machine, enter a build system, or reach production. Coverage spans npm, PyPI, OpenVSX, and beyond, monitoring for suspicious publishing patterns, namespace abuse, typosquatting, and AI-native attack techniques as they emerge.
יעדע געפינס ווערט אויטאמאטיש פּריאָריטיזירט לויט עקספּלויטאַביליטעט, דערגרייכבאַרקייט, און געשעפטלעכע השפּעה, אַזוי אַז אייער מאַנשאַפֿט קאָנצענטרירט זיך אויף וואָס דאַרף טאַקע פֿאַרריכטן ווערן, נישט אויף ראַש.
אויספאָרשן יעדן בייזוויליקן פּעקל און קאַמפּיין וואַלידירט דורך די Xygeni זיכערהייט מאַנשאַפֿט אין די בייזוויליקע קאָד דיידזשעסט.
בלייבט זיכער. בלייבט שנעל. בלייבט אין קאנטראל מיט קסיגעני.




