OpenSourceMalware's human-verified asset watch added 19 records on 20 September, 14 of them marked new to the local archive in that morning's pre-digest brief, and they fall into two shapes. The first is a coordinated install-lifecycle family that executes node index.js on npm install: @shared-web/utils (MAL-2026-16292), @shared-web/assets (MAL-2026-16283), @shared-runtime/modules and @insiderintelligence/googleadmanager (MAL-2026-16290) — precisely the mechanism the npm lifecycle-script approval gate exists to interrupt. The second is imposters and typosquats of popular libraries, four of them rated critical: tailwindcss-forms-ui, which typosquats @tailwindcss/forms behind a 39 KB obfuscated src/index.js (MAL-2026-16295); chai-testing and chai-as-indexed, both flagged for data exfiltration and code execution; and @railone/image-utils, whose index.js spawns a detached, stdio-suppressed process the moment it is imported (MAL-2026-16261). @tink/tink-link-core impersonates the Tink open-banking SDK (MAL-2026-16270) and xzvbailsx redirects the libsignal dependency to a non-registry GitHub source (MAL-2026-16279), while on PyPI requests-auroras and requests-triwes start reverse shells from the install path (MAL-2026-16274, MAL-2026-16275). A second, lower-rated OpenSSF-identified batch — test890-auth, test8999-auth, keroeltop, openmct-heatmap and urc — carries the same instruction: treat any host with these installed as compromised. OSM records the affected version as all for all of them, so the version check belongs to the consumer's own dependency graph.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-20 |
| Source | OpenSourceMalware |
| Reliability | Tier 2 |