What We Caught: July 2026
A month of supply-chain malware on npm — five operations, 33 malicious releases, caught from the live changes feed.
This month codelake confirmed and reported five distinct supply-chain malware operations on npm, spanning 33 malicious package releases. All were caught from the live changes feed — within the window between publication and takedown — and several were novel, not present in OSV or GHSA at detection. Every finding here is structurally confirmed (not an AI-only verdict), was reported to the registry and filed to the OpenSSF Malicious Packages database, and all indicators are defanged. Three patterns recur: the install hook is still the whole attack; payloads escalate and operators cover their tracks; and novel-first-catch, plus an archive that survives the operator's cleanup, is the moat.
One package walked from a recon beacon, through a credential harvester, to a full reverse shell across five releases — then the operator unpublished the entire package to erase it from npm. We had already archived it.
The numbers
Inside this report
Data appendix · key indicators
| Indicator | Value | As of | Primary source |
|---|---|---|---|
| @wagni_bot campaign | 25 packages · wallet/SSH/.env stealer | Jul 2026 | CLR-2026-3000..3024 → |
| date-format-utils-xz | 5 releases · harvester → reverse shell | Jul 2026 | CLR-2026-3039 → |
| supplyhub | 1 release · SSH-key & credential stealer | Jul 2026 | CLR-2026-3038 → |
| tailwind-gutenberg-block-zero | 1 release · download-execute dropper | Jul 2026 | CLR-2026-3037 → |
| faust-cont | 1 release · Deno-as-LOLBin dropper (novel) | Jul 2026 | CLR-2026-3040 → |
Registry counts overlap across indices and must not be summed. Survey figures reflect the cited sample, not the global population.
codelake structural malware analysis (live npm changes feed). All findings reported to npm and filed to the OpenSSF Malicious Packages database with codelake credited as finder. Full advisories with hashes and indicators: research.codelake.dev/advisories. Indicators in this report are defanged.
More from codelake Research
The Silent Patch Problem
When a security fix ships without details, the diff is the vulnerability. A worked example on the WordPress-core "WP2Shell" unauthenticated RCE.
The State of MCP 2026
An annual review of the Model Context Protocol ecosystem: adoption, governance, threat landscape and the emerging security stack.