Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-20 · updated: 2026-09-20 · tags: [incident, global] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

OpenSourceMalware's human-verified asset watch added 19 records on 20 September, 14 of them marked new to the local archive in that morning's pre-digest brief, and they fall into two shapes. The first is a coordinated install-lifecycle family that executes node index.js on npm install: @shared-web/utils (MAL-2026-16292), @shared-web/assets (MAL-2026-16283), @shared-runtime/modules and @insiderintelligence/googleadmanager (MAL-2026-16290) — precisely the mechanism the npm lifecycle-script approval gate exists to interrupt. The second is imposters and typosquats of popular libraries, four of them rated critical: tailwindcss-forms-ui, which typosquats @tailwindcss/forms behind a 39 KB obfuscated src/index.js (MAL-2026-16295); chai-testing and chai-as-indexed, both flagged for data exfiltration and code execution; and @railone/image-utils, whose index.js spawns a detached, stdio-suppressed process the moment it is imported (MAL-2026-16261). @tink/tink-link-core impersonates the Tink open-banking SDK (MAL-2026-16270) and xzvbailsx redirects the libsignal dependency to a non-registry GitHub source (MAL-2026-16279), while on PyPI requests-auroras and requests-triwes start reverse shells from the install path (MAL-2026-16274, MAL-2026-16275). A second, lower-rated OpenSSF-identified batch — test890-auth, test8999-auth, keroeltop, openmct-heatmap and urc — carries the same instruction: treat any host with these installed as compromised. OSM records the affected version as all for all of them, so the version check belongs to the consumer's own dependency graph.

Attribute Detail
Sector Global (Macro)
Date 2026-09-20
Source OpenSourceMalware
Reliability Tier 2