The OpenSourceMalware archive flags a fresh cohort of verified malicious npm assets dated 6 October, distinct from this week's RubyGems crypto-key campaign. Standouts include @subql/common 5.8.3 — a compromised maintainer account pushed a postinstall script decoding an obfuscated infostealer blob (OSV: MAL-2026-17571); tailwindcss-forms-styles, which copies the legitimate @tailwindcss/forms plugin's code verbatim as cover above an IIFE with code-execution and exfiltration (MAL-2026-17524); plus dotenv-promises, with-cte, checkmate-remediation-assistant and serpacksven2, the latter rated "fully compromised if installed." All four-stage human-verified. Ecosystem consumers should treat these as active typosquat/infostealer supply-chain risk rather than noise, and check dependency lockfiles against the advisory OSV/GHSA records.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-07 |
| Source | OpenSourceMalware — @subql/common |
| Reliability | Tier 2 |