The supply-chain watch archived 167 newly verified malicious assets on 30 September, and the batch is dominated by two patterns. The first is name-collision credential theft: dotenv-preflight (npm) presents as a dotenv preflight utility but ships a single heavily obfuscated index.js whose string-array obfuscation has no legitimate purpose in a package of that category, and json-bigint-rs (npm) is a trojanised JSON/WASM library whose WebAssembly module starts a concealed remote-code loader and installs a targeted backdoor in Express applications. Others in the same run include mfahelper, reactjs-risk, runnerx and proxycer across npm and PyPI, several flagged critical and affecting all versions. The second pattern is continuation of the Baileys WhatsApp cluster carried in yesterday's digest, now spread across a widening set of scoped variants — @teamolduser/baileys, @queenanya/baileys, @hanzofc/baileys, @rennnpm/baileys, keithbaileys, xzbails and xzvbails. Assets are human-verified as malicious, but affected versions must be checked against a dependency graph before treating them as an incident.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-01 |
| Source | OpenSourceMalware — dotenv-preflight |
| Reliability | Tier 2 |