# This Week in Malware - Over 100 Packages Discovered

**October 07, 2022**  
By [Aaron Linskens](/content/blog/author/aaron-linskens/index.html)

6 minute read time

This week in malware, we discovered and analyzed more than 100 packages flagged as malicious, suspicious, or dependency confusion attacks in npm and PyPI registries.

## Malicious Packages Caught by Sonatype

We caught the following this week via Sonatype's [automated malware detection system](/content/press-releases/next-generation-nexus-intelligence/index.html), offered as part of [Sonatype Firewall](/content/products/sonatype-repository-firewall/index.html):

1. 1inch  
2. 4ff-lib-foundation  
3. @malware-test-bises-celts-borel-sneak/test-mlw3-bises-celts-borel-sneak  
4. @malware-test-jelly-poled-trull-tokes/test-mlw3-jelly-poled-trull-tokes  
5. @malware-test-lazar-bales-avows-inkle/test-mlw3-lazar-bales-avows-inkle  
6. @malware-test-merge-agony-whits-blate/test-mlw3-merge-agony-whits-blate  
7. @malware-test-piles-perky-glory-sahib/test-mlw3-piles-perky-glory-sahib  
8. @malware-test-pling-pangs-birks-cubit/test-mlw3-pling-pangs-birks-cubit  
9. @schnux/example  
10. @step-security/malware-simulator  
11. ahahjesus  
12. amitbhai  
13. anis-regex  
14. ansi-ergex  
15. ansi-reegx  
16. ansi-regxe  
17. ansi-rgeex  
18. asni-regex  
19. aynmatch  
20. aypports-color  
21. cis-publishers  
22. cloudflare-plugin-frontend  
23. coveragepublisher  
24. cumul.io-integration  
25. cumul.io-plugin-citybikes  
26. cumul.io-plugin-mysql  
27. d2-collection  
28. darshanno1  
29. dcrdata  
30. demozeel  
31. deubg  
32. dexclient  
33. discord-external  
34. dup-glob  
35. dupport-colors  
36. dypports-color  
37. edbug  
38. esrtaverse  
39. estarverse  
40. estraevrse  
41. estraveres  
42. estravesre  
43. estravrese  
44. estrvaerse  
45. ethereum0etl  
46. ethereum2  
47. etsraverse  
48. xxx-sdk-sample-node  
49. example-gke-workload-identity-app  
50. finn-style  
51. futures-sdk  
52. ginore  
53. glob-aprent  
54. ibiza-universe  
55. ignoer  
56. ignroe  
57. imcromatch  
58. ingore  
59. log-status  
60. mciromatch  
61. micormatch  
62. micrmoatch  
63. micro-ed25519-hdkey  
64. microamtch  
65. micromacth  
66. micromtach  
67. mircomatch  
68. navigator-updatertest  
69. naymatch  
70. pip-foo  
71. predpatt  
72. retrap  
73. setraverse  
74. shopify-marketplaces-admin-app  
75. sjesc  
76. soupports-colors  
77. spuports-color  
78. srv-configs  
79. suopport-colors  
80. supoprts-color  
81. supporst-color  
82. supports-cloor  
83. supports-colro  
84. supports-coolr  
85. supports-oclor  
86. suppotrs-color  
87. supprots-color  
88. suypport-colors  
89. sypport-color  
90. syupport-colors  
91. tds-publish  
92. tensorflow-estimator-2.0-preview  
93. test-mlw1-bises-celts-borel-sneak  
94. test-mlw1-goals-roker-elmen-bongo  
95. test-mlw1-karat-jowar-scurs-pearl  
96. test-mlw1-noops-semis-edict-bokes  
97. test-mlw1-ogres-bogle-kakas-bogus  
98. test-mlw1-picky-argal-cried-alloy  
99. test-mlw1-piles-perky-glory-sahib  
100. test-mlw1-pling-pangs-birks-cubit  
101. test-mlw1-rakee-clasp-mudir-ovoid  
102. test-mlw1-salto-drags-hunks-chiao  
103. test-mlw1-tasty-fazed-witan-quins  
104. test-mlw2-bises-celts-borel-sneak  
105. test-mlw2-picky-argal-cried-alloy  
106. test-mlw2-pling-pangs-birks-cubit  
107. test-mlw2-salto-drags-hunks-chiao  
108. test-mlw2-tasty-fazed-witan-quins  
109. tlsib  
110. tomcrypt  
111. tsilb  
112. tslbi  
113. uspports-color  
114. utility-common-v2  
115. wanger  
116. warprnnt-pytorch  
117. webcm-dev  
118. websocket-template  
119. Y1zh3e7

These discoveries follow [our report last week](/content/blog/this-week-in-malware-sept-30-22/index.html) of over 130 new packages discovered.

## Turn on Sonatype Firewall for Automatic Protection

As a [DevSecOps](/content/resources/articles/what-is-devsecops/index.html) organization, we remain committed to identifying and halting attacks, such as those mentioned above, against open source developers and the wider [software supply chain](/content/resources/articles/what-is-software-supply-chain/index.html).

Users of Sonatype Firewall can rest easy knowing that such malicious packages would automatically be blocked from reaching their development builds.

Sonatype Firewall instances will automatically quarantine any suspicious components detected by our automated malware detection systems, while a researcher is in progress, thereby keeping your software supply chain protected from the start.

Sonatype's world-class security research data, combined with our [automated malware detection](/content/press-releases/next-generation-nexus-intelligence/index.html) technology, protects your developers, customers, and software supply chain from infections.

Written by **Aaron Linskens**  
Aaron is a technical writer at Sonatype. He works at a crossroads of technical writing, developer advocacy, and information design. He aims to get developers and non-technical collaborators to work better together in solving problems and building software.
