Review dependency confusion findings, where a public package can be installed in place of an intended private dependency. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 08:48 UTC. Ordered by latest scan.
The package performs unsolicited external callbacks during installation through a postinstall hook. This is concrete dependency-confusion install tracking and warrants blocking.
The package performs concealed, unconsented modification of a foreign project manifest during postinstall. No network or credential theft was found, but dependency injection alone is conc...
The package's only observable behavior is an unconsented postinstall mutation of the consumer project to inject another dependency. This is a concrete supply-chain attack behavior despite...
This is confirmed unconsented install-time metadata collection and file creation in a package explicitly positioned as a dependency-confusion PoC. Absence of network exfiltration does not...