Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 02:27 UTC. Refreshes when new reports are published.
The source establishes intentional install-time execution and an external callback, not merely a static hint. Although no payload download or file modification was found, this is concrete...
Despite benign/authorized claims, the source implements unconsented install-time reconnaissance and outbound exfiltration as a dependency-confusion proof of execution. That is concrete at...
Source inspection confirms an unconsented postinstall network beacon that transmits CI/project and host identifiers, matching a dependency-confusion canary rather than inert placeholder c...
Source inspection confirms a lifecycle-triggered dependency-confusion PoC with external install pingback and persistent identifier, which is concrete unconsented behavior even though it d...