Campaign analyses and threat intelligence. We link malicious packages, models, skills, MCP servers, extensions, and containers to the wider operations behind them.
vulndify-mcp-server 0.3.0 describes itself on PyPI as a minimal demo exposing a single hello tool. The published code registers three tools. One of them downloads a remote script and executes it, deserializes caller-supplied pickle data, and pipes the same URL through a shell.
@andrewstory18/is-real-odd ships the genuine is-odd source untouched, so anything that imports it behaves normally. The package.json is a verbatim copy of the original manifest with two additions, a postinstall hook and a second file for it to run. That file is machine-obfuscated and, decoded, posts to a hardcoded address on port 3000 at install time. The payload collects nothing yet, and the effort spent hiding it is the reason to look closer.
The npm package @yancyyu/agentcli, published by the account yancyyu, presents as an AI engineering collaboration tool with a real feature set. Inside it is a routine that extracts the four Lark client secrets from the operating-system protected store, refreshes them against the real Feishu login service so they stay valid, and posts them to a backend the code calls AgentBus. On install it also seeds files into the developer Claude Code configuration directory. The 169 MB of bundled native binaries keep most of the code out of reach of size-capped review.
crypto-checkout-api and wallet-analytics ship the same loader under different names from the account ahmad318. A decoy function fetches real icons from a public CDN while the exported getPlugin pulls JavaScript from a raw IP command server and runs it through new Function with full Node.js privileges. The declared dependencies are a credential-theft toolkit. A third package in the operation, react-svg-helper, has already been seized by npm.
korvath and korvica, published by the account kilomev, and streak-daily-lib, published by taipen_chat, present as calendar and streak math libraries. The consumer package is harmless. The payload rides in a helper that runs on import, detects a Windows Subsystem for Linux developer machine, downloads an executable from a shared file-hosting bucket, and writes it into the Windows Startup folder for logon persistence. The three packages link to one operation at high confidence.
tchain-api (published by the account hallisaacpna555) poses as a Turborepo and Next.js monorepo while carrying two CryptoJS-encrypted blobs, rsa.db and des.db, plus a module that reads both and re-exports them as rsaKey and desKey. The module neither decrypts nor runs that material, and no network activity ships in this version. The carrier structure matches the encrypted-payload tradecraft previously documented in the thedata package, at moderate confidence.
ai-pro-sdk (published July 14, 2026 by arslan310kiran) presents itself as an unofficial AI SDK v7 provider for Claude. The legitimate wrapper code re-exports the real @anthropic-ai/claude-agent-sdk. Appended to the same file is a loader that imports a DES-encrypted blob from the publisher own data-blockv package, decrypts it, and spawns it as a detached child process. The decrypted payload is heavily obfuscated JavaScript that silently installs axios and socket.io-client, contacts a hardcoded C2 server over HTTP, decrypts a second-stage script using AES-256-CBC, writes it to the OS temp directory, and executes it. A parallel campaign targeting blockchain developers uses the same pattern through chain-sdk-js and its dependency thedata, published by a second account.
Five malicious versions of the official jscrambler npm package (8.14.0 through 8.20.0) were published on July 11, 2026, each dropping a cross-platform Rust infostealer that targets browser credentials, crypto wallets, and session tokens. The adversary adapted mid-attack, switching from a blockable preinstall hook to a runtime dropper that bypasses ignore-scripts.
The npm account justhunter publishes 10 packages across namespaces belonging to Microsoft, Nuxt, Shopify, HarvardX, and Adobe. Several describe themselves as security research canaries. At least one, gen-ai-opt-in, runs a postinstall that collects the developer IP address, hostname, username, and geolocation and sends it to a Burp Suite Collaborator callback. The tooling and data collection are consistent with dependency confusion research. The packages still execute code and exfiltrate data without consent.
claude-token-tracker-mcp poses as a cost-monitoring MCP server for Claude Code. It registers six tools that return fabricated data while collecting Claude configuration files, shell history containing secrets, and API key environment variables. The collected data is uploaded anonymously to a public file-hosting service on load, on every tool call, and hourly.
The account behind four fake AI helper packages has shipped a fifth, anthropic-toolkit, targeting the Anthropic SDK. It runs the same developer-recon postinstall and reports to the same Google Cloud Run endpoint, published about a day after the first wave. Because the operation was already on file, the new package is a match rather than a fresh investigation.
Four npm packages published by the account arielsimon impersonate helper libraries for Ollama, the OpenAI Agents SDK, the Vercel AI SDK, and LangGraph.js. All four run identical postinstall scripts that harvest developer identity, SSH key emails, Git reflog history, GitHub CLI credentials, and cloud configuration, then exfiltrate everything to the same Google Cloud Run endpoint. The scripts wrap the collection in detailed telemetry comments designed to survive code review.
ts-precision ships a trojanized copy of the legitimate big.js v7.0.1 library with injected code that loads data-parser-utils, a crypto wallet stealer, at runtime. stake-math downloads and executes a remote payload bundle from log-prettier[.]store while exporting a working Kelly criterion library. data-parser-utils, the core infostealer, uploads stolen wallet files, shell history, and Telegram sessions to a Vercel endpoint. All three trace to one adversary with high confidence.
Two Hugging Face repositories published serialized files named like ONNX and GGUF models that are actually Python pickles which run a shell command when loaded. The payload is a benign proof of concept, and both artifacts trace to a single author whose intent, research or reconnaissance, is unresolved.
A compromised npm developer account distributed credential-stealing payloads through 23 packages with roughly 52,000 combined monthly downloads. The payload runs under Bun to evade Node-based detection, harvests credentials from cloud providers and CI platforms, and weaponizes them to poison packages across npm, PyPI, RubyGems, and JFrog Artifactory, tracing to a multi-wave operation with high confidence.