OpenSourceMalware's asset watch — a four-stage community verification pipeline — added 36 records across npm (30) and PyPI (6) in its 20–21 September harvests (979 in the archive), dominated by packages impersonating well-known libraries. The most notable is tailwind-form-styles (critical), which OSM describes as a DPRK package posing as a Tailwind utility, alongside tailwindcss-forms-ui, which typosquats @tailwindcss/forms and whose main entry diverges from the genuine package (MAL-2026-16295). A chai cluster — chai-as-viem, chai-testing and chai-as-indexed, all rated critical for data exfiltration and code execution — uses the same imposter shape as this edition's lead story, as does @tink/tink-link-core, which impersonates the Tink open-banking SDK (MAL-2026-16270). On PyPI, three requests imposters — requests-auroras, requests-triwes and requests-asetwe — start reverse shells or exfiltrate on install, as does py-venv-doctor (MAL-2026-16296). Two clusters stand out for what they target: five Baileys WhatsApp-library forks (zero-baileys, @lekzo/baileys, xzvbailey, xzvbailsx, xzvexpzcbailey) redirect the libsignal dependency to a non-registry GitHub source, and marketing-mcp (MAL-2026-16250) attempts to lure LLM agents into exfiltrating files. OSM records the affected version as all for these entries, so the version check is the consumer's — confirm against your own dependency graph before treating a project as affected.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-21 |
| Source | OpenSourceMalware |
| Reliability | Tier 2 |