Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 01:27 UTC. Refreshes when new reports are published.
This is confirmed unconsented install-time metadata collection and file creation in a package explicitly positioned as a dependency-confusion PoC. Absence of network exfiltration does not...
The package has an unconsented postinstall that collects system/user data and mutates the filesystem, explicitly presented as dependency-confusion proof behavior. No exfiltration endpoint...
The source establishes intentional install-time execution and an external callback, not merely a static hint. Although no payload download or file modification was found, this is concrete...
The lifecycle script silently hijacks another package's namespace, and runtime code performs undisclosed remote-controlled activity through user credentials. These are concrete malicious...