This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. @andrewstory18/is-real-odd (npm)
- Package: https://www.npmjs.com/package/@andrewstory18/is-real-odd
- Severity: high
- Affected versions: all
- Downloads: 2460805
- First seen: 1 August 2026 at 09:55 UTC
Typosquat of the well-known is-odd package (copied name, description, README, and false author credit to Jon Schlinkert). The
legitimate-looking index.js is a decoy; the actual payload is index.min.js, obfuscated with Obfuscator.io techniques (string-array rotation, hex identifiers) and executed automatically via a postinstall hook ("postinstall": "node index.min.js"). On every install it silently opens an outbound HTTP connection to a
hardcoded external IP — a classic install-time beacon / first-stage check-in. Detected by static analysis (OBF-028 obfuscator.io string-array rotation,
OBF-014 hex identifiers, MANIFEST-007 install-hook execution) and confirmed by manual code review including deobfuscation. Publisher identity unknown (npm has taken the package down and stripped maintainer data). SHA-256 of package tarball: 4adae43c35fac26e0965c8ee525e6b54f4ec129c52274b8ecb5ca6bbe1b213aa
References: https://www.npmjs.com/package/@andrewstory18/is-real-odd/v/2.0.3 http://144.172.91.84:3000/hello
2. @injectivelabs/networks (npm)
- Package: https://www.npmjs.com/package/@injectivelabs/networks
- Severity: critical
- Affected versions: 1.20.21
- Downloads: 40248
- First seen: 29 July 2026 at 00:42 UTC
@injectivelabs/[email protected] is one of 17 packages in the @injectivelabs ecosystem that pinned @injectivelabs/[email protected] as a dependency, transitively delivering the malicious payload to downstream consumers. The package receives approximately 42,785 weekly downloads. The malicious code resides entirely in sdk-ts — see https://opensourcemalware.com/npm/@injectivelabs/sdk-ts for full technical details.
The other affected packages in this ecosystem are: @injectivelabs/utils, @injectivelabs/ts-types, @injectivelabs/exceptions, @injectivelabs/wallet-base, @injectivelabs/wallet-core, @injectivelabs/wallet-cosmos, @injectivelabs/wallet-private-key, @injectivelabs/wallet-evm, @injectivelabs/wallet-trezor, @injectivelabs/wallet-cosmostation, @injectivelabs/wallet-ledger, @injectivelabs/wallet-wallet-connect, @injectivelabs/wallet-magic, @injectivelabs/wallet-strategy, @injectivelabs/wallet-turnkey, @injectivelabs/wallet-cosmos-strategy (all version 1.20.21). Safe action: upgrade to 1.20.23 or later and immediately rotate any cryptocurrency credentials (mnemonic phrases, private keys) processed while the compromised version was installed.
References: https://github.com/InjectiveLabs/injective-ts/issues/697, https://socket.dev/blog/compromised-injective-sdk-npm-package
3. @injectivelabs/exceptions (npm)
- Package: https://www.npmjs.com/package/@injectivelabs/exceptions
- Severity: critical
- Affected versions: 1.20.21
- Downloads: 39923
- First seen: 25 July 2026 at 22:42 UTC
@injectivelabs/[email protected] is one of 17 packages in the @injectivelabs ecosystem that pinned @injectivelabs/[email protected] as a dependency, transitively delivering the malicious payload to downstream consumers. The package receives approximately 39,923 weekly downloads. The malicious code resides entirely in sdk-ts — see https://opensourcemalware.com/npm/@injectivelabs/sdk-ts for full technical details. The other affected packages in this ecosystem are: @injectivelabs/utils, @injectivelabs/networks, @injectivelabs/ts-types, @injectivelabs/wallet-base, @injectivelabs/wallet-core, @injectivelabs/wallet-cosmos, @injectivelabs/wallet-private-key, @injectivelabs/wallet-evm, @injectivelabs/wallet-trezor, @injectivelabs/wallet-cosmostation, @injectivelabs/wallet-ledger, @injectivelabs/wallet-wallet-connect, @injectivelabs/wallet-magic, @injectivelabs/wallet-strategy, @injectivelabs/wallet-turnkey, @injectivelabs/wallet-cosmos-strategy (all version 1.20.21). Safe action: upgrade to 1.20.23 or later and immediately rotate any cryptocurrency credentials (mnemonic phrases, private keys) processed while the compromised version was installed.
References: https://github.com/InjectiveLabs/injective-ts/issues/697, https://socket.dev/blog/compromised-injective-sdk-npm-package
4. @injectivelabs/ts-types (npm)
- Package: https://www.npmjs.com/package/@injectivelabs/ts-types
- Severity: critical
- Affected versions: 1.20.21
- Downloads: 38817
- First seen: 29 July 2026 at 00:42 UTC
@injectivelabs/[email protected] is one of 17 packages in the @injectivelabs ecosystem that pinned @injectivelabs/[email protected] as a dependency, transitively delivering the malicious payload to downstream consumers. The package receives approximately 41,610 weekly downloads. The malicious code resides entirely in sdk-ts — see https://opensourcemalware.com/npm/@injectivelabs/sdk-ts for full technical details.
The other affected packages in this ecosystem are: @injectivelabs/utils, @injectivelabs/networks, @injectivelabs/exceptions, @injectivelabs/wallet-base, @injectivelabs/wallet-core, @injectivelabs/wallet-cosmos, @injectivelabs/wallet-private-key, @injectivelabs/wallet-evm, @injectivelabs/wallet-trezor, @injectivelabs/wallet-cosmostation, @injectivelabs/wallet-ledger, @injectivelabs/wallet-wallet-connect, @injectivelabs/wallet-magic, @injectivelabs/wallet-strategy, @injectivelabs/wallet-turnkey, @injectivelabs/wallet-cosmos-strategy (all version 1.20.21). Safe action: upgrade to 1.20.23 or later and immediately rotate any cryptocurrency credentials (mnemonic phrases, private keys) processed while the compromised version was installed.
References: https://github.com/InjectiveLabs/injective-ts/issues/697, https://socket.dev/blog/compromised-injective-sdk-npm-package
5. @injectivelabs/utils (npm)
- Package: https://www.npmjs.com/package/@injectivelabs/utils
- Severity: critical
- Affected versions: 1.20.21
- Downloads: 38063
- First seen: 29 July 2026 at 00:42 UTC
@injectivelabs/[email protected] is one of 17 packages in the @injectivelabs ecosystem that pinned @injectivelabs/[email protected] as a dependency, transitively delivering the malicious payload to downstream consumers. The package receives approximately 43,940 weekly downloads. The malicious code resides entirely in sdk-ts — see https://opensourcemalware.com/npm/@injectivelabs/sdk-ts for full technical details.
The other affected packages in this ecosystem are: @injectivelabs/networks, @injectivelabs/ts-types, @injectivelabs/exceptions, @injectivelabs/wallet-base, @injectivelabs/wallet-core, @injectivelabs/wallet-cosmos, @injectivelabs/wallet-private-key, @injectivelabs/wallet-evm, @injectivelabs/wallet-trezor, @injectivelabs/wallet-cosmostation, @injectivelabs/wallet-ledger, @injectivelabs/wallet-wallet-connect, @injectivelabs/wallet-magic, @injectivelabs/wallet-strategy, @injectivelabs/wallet-turnkey, @injectivelabs/wallet-cosmos-strategy (all version 1.20.21). Safe action: upgrade to 1.20.23 or later and immediately rotate any cryptocurrency credentials (mnemonic phrases, private keys) processed while the compromised version was installed.
References: https://github.com/InjectiveLabs/injective-ts/issues/697, https://socket.dev/blog/compromised-injective-sdk-npm-package
6. @joyfill/components (npm)
- Package: https://www.npmjs.com/package/@joyfill/components
- Severity: critical
- Affected versions: 4.0.0-rc24-2773-beta.4
- Downloads: 20980
- First seen: 28 July 2026 at 19:20 UTC
@joyfill/components version 4.0.0-rc24-2773-beta.4 was compromised and published on July 28, 2026 as part of the PolinRider campaign (DPRK/Lazarus Group), using the same blockchain C2 infrastructure documented by OpenSourceMalware in numerous malicious packages. Unlike previous PolinRider packages, which used disposable npm accounts or stolen GitHub identities, this is a legitimate Joyfill beta release — meaning the attacker needed to compromise an existing maintainer account to publish it. The exact mechanism (credential theft, phishing, session hijack) is not confirmed in available reporting. Malicious code appended after legitimate package code executes at module import time, delivering InvisibleFerret (also tracked as DEV#POPPER RAT). The sibling compromised package is @joyfill/[email protected]. Safe action: pin to a non-beta release and rotate all credentials on affected machines.
References: https://socket.dev/blog/joyfill-npm-beta-releases-compromised, https://opensourcemalware.com/blog/chainveil-and-vitevenom-dprk-polinrider-campaign, https://opensourcemalware.com/blog/tasksjacker-dprk-attack-github-vscode
7. @joyfill/layouts (npm)
- Package: https://www.npmjs.com/package/@joyfill/layouts
- Severity: critical
- Affected versions: 0.1.2-2773.beta.0
- Downloads: 20004
- First seen: 28 July 2026 at 19:20 UTC
@joyfill/layouts version 0.1.2-2773.beta.0 was compromised and published on July 28, 2026 as part of the PolinRider campaign (DPRK/Lazarus Group), using the same blockchain C2 infrastructure documented by OpenSourceMalware in numerous malicious packages. Unlike previous PolinRider packages, which used disposable npm accounts or stolen GitHub identities, this is a legitimate Joyfill beta release — meaning the attacker needed to compromise an existing maintainer account to publish it. The exact mechanism (credential theft, phishing, session hijack) is not confirmed in available reporting. Malicious code appended after legitimate package code executes at module import time, delivering InvisibleFerret (also tracked as DEV#POPPER RAT). The sibling compromised package is @joyfill/[email protected]. Safe action: pin to a non-beta release and rotate all credentials on affected machines.
References: https://socket.dev/blog/joyfill-npm-beta-releases-compromised, https://opensourcemalware.com/blog/chainveil-and-vitevenom-dprk-polinrider-campaign, https://opensourcemalware.com/blog/tasksjacker-dprk-attack-github-vscode
8. @yancyyu/agentcli (npm)
- Package: https://www.npmjs.com/package/@yancyyu/agentcli
- Severity: critical
- Affected versions: 1.9.80
- Downloads: 6670
- First seen: 28 July 2026 at 15:34 UTC
This package exhibits the FNOS infostealer attacker model: it targets AI developers using Claude Code by embedding a postinstall hook that patches dependency installers, spawns detached background processes with suppressed I/O (bin/lib/auth.mjs, src/main/server.ts), writes persistence to .bashrc (bin/lib/aikey.mjs), and exfiltrates environment variables, git config, and platform info. The smoking-gun IOC is the literal Feishu bot webhook URL https://open.feishu.cn/open-apis/bot/v2/hook/43a9288c-64b5-4344-9b8f-f27bf75b10ca in src/main/telemetry/larkCredentials.ts, which matches the FNOS malware family's canonical C2 channel. Two hardcoded Chinese IP literals (47.112.24.153 and 159.75.231.98) corroborate server-side infrastructure. The package's deep integration with the .claude directory tree — reading project configs and session data — confirms it is specifically targeting Claude Code users' AI API keys and credentials. The combination of install-time hook, stealth persistence, env-var and git-config exfil, and Feishu webhook C2 maps cleanly to the FNOS/supply-chain infostealer playbook.
9. @injectivelabs/wallet-base (npm)
- Package: https://www.npmjs.com/package/@injectivelabs/wallet-base
- Severity: critical
- Affected versions: 1.20.21
- Downloads: 2804
- First seen: 25 July 2026 at 23:36 UTC
@injectivelabs/[email protected] is one of 17 packages in the @injectivelabs ecosystem that pinned @injectivelabs/[email protected] as a dependency, transitively delivering the malicious payload to downstream consumers. The package receives approximately 2,804 weekly downloads. The malicious code resides entirely in sdk-ts — see https://opensourcemalware.com/npm/@injectivelabs/sdk-ts for full technical details. The other affected packages in this ecosystem are: @injectivelabs/utils, @injectivelabs/networks, @injectivelabs/ts-types, @injectivelabs/exceptions, @injectivelabs/wallet-core, @injectivelabs/wallet-cosmos, @injectivelabs/wallet-private-key, @injectivelabs/wallet-evm, @injectivelabs/wallet-trezor, @injectivelabs/wallet-cosmostation, @injectivelabs/wallet-ledger, @injectivelabs/wallet-wallet-connect, @injectivelabs/wallet-magic, @injectivelabs/wallet-strategy, @injectivelabs/wallet-turnkey, @injectivelabs/wallet-cosmos-strategy (all version 1.20.21). Safe action: upgrade to 1.20.23 or later and immediately rotate any cryptocurrency credentials (mnemonic phrases, private keys) processed while the compromised version was installed.
References: https://github.com/InjectiveLabs/injective-ts/issues/697, https://socket.dev/blog/compromised-injective-sdk-npm-package
10. xerohub-discord-voice-v2 (npm)
- Package: https://www.npmjs.com/package/xerohub-discord-voice-v2
- Severity: high
- Affected versions: all
- Downloads: 2572
- First seen: 28 July 2026 at 14:55 UTC
Malicious package detected.
Want help mitigating malicious packages before they reach your network?
ShieldedStack acts as a security proxy in front of npm, PyPI, NuGet, and Maven, helping teams detect and block malicious or risky packages before they reach developer machines or CI pipelines.
Learn more: https://shieldedstack.com
Credits for the core data goes to https://opensourcemalware.com