恶意代码摘要 84

Xygeni 恶意代码摘要 84

Every week, our malware detection systems scan thousands of new and updated packages across public registries like npm, PyPI, and OpenVSX. We confirmed 34 malicious packages between August 15 and August 20, 2026, led by a sustained impersonation campaign against Baileys, a popular open-source WhatsApp Web API library, a cluster of Twilio/HackerOne-branded probe packages, and a set of unrelated-looking npm packages sharing an identical, unusually high version number.

The Baileys impersonation ran the longest: four separate package names (@mrlegendbot/baileys, cloud-baileys, @vanzxy/baileys, ourin-baileys) confirmed across six days, with cloud-baileys alone republished four times between August 15 and 20 under climbing version numbers, a pattern consistent with an attacker iterating past detection rather than a one-off upload.

A separate cluster on August 15 published packages referencing Twilio and HackerOne (twilio-hackerone-poc-afe6937c, five versions in one day, plus tw-pkgprobe-7731hunterone-build-probe-9210), naming conventions typically associated with bug-bounty or dependency-confusion probing rather than a disguised payload.

还有一点值得注意: pump-segments-sdk, carbon-monorepopump-fun-skills, three otherwise unrelated package names all published at version 20.1.1 on August 19, an unusual shared version number across supposedly independent projects that suggests a single actor behind all three.

每周快照是我们正在进行的 恶意代码摘要, where we validate new threats to help DevSecOps teams protect their pipeline在损害发生之前。

生态系统 小包装 日期
NPMhunterone-build-probe-9210:1.0.02026 年 8 月 15 日
NPMtwilio-hackerone-poc-afe6937c:1.0.02026 年 8 月 15 日
NPMtw-pkgprobe-7731:1.0.02026 年 8 月 15 日
NPMtwilio-hackerone-poc-afe6937c:1.0.12026 年 8 月 15 日
NPMtwilio-hackerone-poc-afe6937c:1.0.22026 年 8 月 15 日
NPMtwilio-hackerone-poc-afe6937c:1.0.32026 年 8 月 15 日
NPMtwilio-hackerone-poc-afe6937c:1.0.42026 年 8 月 15 日
NPM@mrlegendbot/baileys:1.2.42026 年 8 月 15 日
NPMcloud-baileys:1.1.32026 年 8 月 15 日
NPM@vanzxy/baileys:1.4.22026 年 8 月 16 日
NPMourin-baileys:9.0.112026 年 8 月 16 日
NPMeyiouss:4.0.12026 年 8 月 16 日
NPMcloud-baileys:1.1.332026 年 8 月 16 日
NPMmoidev:1.0.02026 年 8 月 16 日
NPM@wangjiezhong/dsh-memory:0.1.12026 年 8 月 17 日
NPM@wangjiezhong/dsh-memory:0.1.22026 年 8 月 17 日
NPM@wangjiezhong/dsh-memory:0.1.32026 年 8 月 17 日
NPM@wangjiezhong/dsh-memory:0.1.42026 年 8 月 17 日
NPMmoidevx:1.0.02026 年 8 月 17 日
NPMdxr-dos:0.1.22026 年 8 月 17 日
NPMdxr-dos:0.1.12026 年 8 月 17 日
NPMdxr-dos:0.1.32026 年 8 月 17 日
NPMcloud-baileys:1.1.342026 年 8 月 18 日
pireqcrypt:0.1.02026 年 8 月 18 日
NPMdxrs-dos:0.1.32026 年 8 月 18 日
NPMprism-registry:1.0.12026 年 8 月 18 日
NPMoptimizely-starter-kit-for-fastly-compute:1.0.12026 年 8 月 18 日
NPM@mohamed_nowisar/canary-confirm-token3:0.0.12026 年 8 月 18 日
NPM@mohamed_nowisar/depconf-canary-test:0.0.12026 年 8 月 18 日
NPM@mohamed_nowisar/token3-check:0.0.12026 年 8 月 18 日
NPMpump-segments-sdk:20.1.12026 年 8 月 19 日
NPMcarbon-monorepo:20.1.12026 年 8 月 19 日
NPMpump-fun-skills:20.1.12026 年 8 月 19 日
NPMcloud-baileys:1.1.352026 年 8 月 20 日

When Iteration Beats Detection: 34 Malicious Packages This Week

This week’s digest shows attackers leaning on persistence rather than a single lucky upload. The cloud-baileys impersonation of the popular WhatsApp Web API library was republished four separate times between August 15 and 20 under climbing version numbers, joined by three other lookalike names (@mrlegendbot/baileys, @vanzxy/baileys, ourin-baileys), a sustained campaign rather than a one-off attempt.

Naming conventions gave other clusters away just as fast. A group of packages branded around Twilio and HackerOne, including twilio-hackerone-poc-afe6937c published in five versions in a single day, alongside tw-pkgprobe-7731hunterone-build-probe-9210, used naming patterns typically associated with bug-bounty or dependency-confusion probing. Elsewhere, three unrelated package names (pump-segments-sdk, carbon-monorepo, pump-fun-skills) all shipped under the identical version number 20.1.1 on the same day, an unusual coincidence that points to one actor operating behind all three.

Xygeni 早期恶意软件警告 monitors npm, PyPI, Maven, OpenVSX, and other registries in real time, flagging threats at the moment of publication, before they reach a build and before an AI agent installs them autonomously. When the same package name resurfaces four times in six days under a new version each time, detection that only checks once is already behind.

Xygeni 的 Open Source Security 该平台为 DevSecOps 团队提供实时检测和优先级排序功能,帮助他们应对协调供应链带来的压力,从而保障您的安全。 pipeline保持清洁,同时又不拖慢团队速度。

sca-tools-软件-成分分析工具
确定软件风险的优先级、进行补救并加以保护
注册免费账号。
不需要信用卡。

保护您的软件开发和交付

使用 Xygeni 产品套件