Review dependency confusion findings, where a public package can be installed in place of an intended private dependency. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 08:48 UTC. Ordered by latest scan.
The package performs unsolicited external callbacks during installation through a postinstall hook. This is concrete dependency-confusion install tracking and warrants blocking.
The package's only observable behavior is an unconsented postinstall mutation of the consumer project to inject another dependency. This is a concrete supply-chain attack behavior despite...
The source establishes intentional install-time execution and an external callback, not merely a static hint. Although no payload download or file modification was found, this is concrete...
The lifecycle script silently hijacks another package's namespace, and runtime code performs undisclosed remote-controlled activity through user credentials. These are concrete malicious...