LPM Firewall checks package versions and transitive dependencies against live malware intelligence, AI review, and product-security policy blocks. Blocked package versions are stopped before they ever reach your machine.
Latest blocked packages.
The newest package versions blocked by the firewall, including malware, data exfiltration, remote code execution, and AI-agent control-surface risks.
Source confirms concrete postinstall persistence into ~/.claude/skills and ~/.claude/agents plus runtime npm installation. This meets the install-control-surface block policy.
The package's automatic postinstall installs behavior-bearing hooks and skills into global Claude and .agents locations, not merely its own package directory. This meets the blocking poli...
The advertised server utility embeds an undisclosed global install and stealthy background process launch to a remote API. Although it is runtime-triggered rather than npm lifecycle-trigg...
The package embeds an undisclosed external script and an obfuscated fetch-plus-new-Function loader activated by opening its page. This is a concrete remote code execution surface, not mer...
The source documents and implements an install-time unsigned native payload delivery chain designed to avoid OS security warnings. Bundled checksum validation does not negate the intentio...
Direct source inspection confirms an unconsented postinstall write to global AI-agent skill locations. Collision checks reduce overwrite risk but do not remove the foreign control-surface...
This is concrete runtime data exfiltration, not merely a capability library: clipboard transmission starts automatically when the CLI runs. The absence of an install hook limits install-t...
Runtime execution automatically exfiltrates arbitrary clipboard changes to a remote endpoint and provides screenshot upload through a stealth interface. The absence of lifecycle hooks lim...
The package embeds a concealed, cryptographically gated decrypt-and-spawn chain in its primary Mutex implementation. This is concrete malicious runtime behavior, not an unused static prim...
Turn on Firewall through LPM.
Start with LPM CLI, become Pro on lpm.dev, then enable Firewall from lpm config. Your package installs keep the speed of LPM with an extra package-version block layer in front.
Install LPM CLI from cli.lpm.dev. It is already faster and more secure for npm installs, even before Firewall is enabled.
Upgrade on lpm.dev so your account can use LPM Firewall protection across package installs.
Open LPM CLI, enable Firewall from lpm config, and route package installs through the protected registry.
Start with LPM CLI, then enable Firewall.
Install the faster and more secure CLI, upgrade to Pro on lpm.dev, and enable Firewall from lpm config when you are ready.