Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm and PyPI. This week was no exception. We confirmed 165 malicious packages between July 17 and July 24, 2026, across npm and PyPI, led by one high-velocity campaign and several new impersonation clusters.
Iṣẹlẹ kan ṣoṣo ti o tobi julọ ni bingo-ai on PyPI, again: nearly 85 versions confirmed in a 23-minute window on July 21, the same automated publishing pattern we flagged in this package last week.
We also confirmed further activity from gcli-control on PyPI, a package our research team profiled in detail this week: a fully-featured Windows RAT (keylogging, webcam/mic capture, clipboard monitoring, browser-credential theft, persistence) that routes its command-and-control through npoint.io, a free JSON-hosting service, rather than an attacker-owned domain. The initial burst (versions 0.1.0 to 0.7.1) escalated to full capability in about 13.5 hours on July 21–22. This week’s digest shows the campaign didn’t stop there: five more versions (0.8.0 through 0.12.0) followed at a steadier pace through July 23–24.
We also confirmed a nine-package Twilio impersonation cluster on npm (twilio-serverless, twilio-functions, twilio-internal, and others), all published July 21 with inflated version numbers, a classic dependency-confusion pattern. A second cluster targeted crypto/DeFi tooling on npm, nine packages including uniswap-sdk-v4, wagmi-react, Ati ethers-secure, published July 23.
Smaller but notable: a repeating “date formatting utility” naming theme across three separate campaigns, and n8n-nodes-pwn, a suspiciously named automation-node package confirmed July 22.
Àwòrán ọ̀sọ̀ọ̀sẹ̀ yìí jẹ́ ara àwọn àwòrán tí a ń yà lọ́wọ́lọ́wọ́ Àkójọpọ̀ Kóòdù Ìwà Ìbàjẹ́níbi tí a ti ń fìdí àwọn ìhalẹ̀mọ́ tuntun múlẹ̀ àti láti pèsè ìmọ̀ tó ṣeé ṣe láti ran àwọn ẹgbẹ́ DevSecOps lọ́wọ́ láti dáàbò bo pipelinekí ìbàjẹ́ tó ṣẹlẹ̀. Ẹ jẹ́ ká ṣàlàyé ohun tí a rí ní ọ̀sẹ̀ yìí àti ìdí tí ó fi ṣe pàtàkì.
Àwọn àpò 165+. Ọ̀sẹ̀ kan. Ìwọ̀n náà ń gùn sí i.
Àkójọpọ̀ ọ̀sẹ̀ yìí fi irú ipa kan náà hàn: àwọn olùkọlù máa ń tẹ̀ jáde kíákíá ju bí àwọn olùforúkọsílẹ̀ ṣe máa yọ kúrò lọ, àti kíákíá ju bí ìwòsàn ọ̀sọ̀ọ̀sẹ̀ kan ṣe lè mú lọ. Àpò PyPI kan ṣoṣo, bingo-ai, went from first version to nearly 85 confirmed versions in about 23 minutes, automated publishing at a speed no manual review process can match. Meanwhile, gcli-control shows that volume isn’t the only risk: a fully-featured RAT that didn’t bother hiding what it was, instead relaying its commands through npoint.io, a free JSON-hosting service, so its traffic blends into ordinary developer activity with no attacker-owned domain to block. And the Twilio and crypto/DeFi impersonation clusters show a third pattern entirely: coordinated, multi-package drops using inflated version numbers to win a dependency-confusion race against internal package names.
Ìkìlọ̀ nípa Àìlera Àìsàn Xygeni ní Ìbẹ̀rẹ̀ monitors npm, PyPI, and other registries in real time, flagging threats at the moment of publication, before they reach a build, before an AI agent installs them autonomously, and before a covert relay or a dependency-confusion package has a chance to execute. When bingo-ai ships dozens of versions in under half an hour, or gcli-control routes its C2 through a service your egress rules already allow, detection that runs after the fact is already too late.
Xygeni's Open Source Security pẹpẹ náà fún àwọn ẹgbẹ́ DevSecOps ní àwárí àti àfikún àkókò gidi tí wọ́n nílò láti wà níwájú ìfúnpọ̀ pq ìpèsè tí a ṣètò, nítorí náà ìwọ pipelineẸ jẹ́ kí àwọn ẹgbẹ́ yín wà ní mímọ́ láìsí ìdíwọ́.






