Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 02:26 UTC. Refreshes when new reports are published.
This is concrete, obfuscated, install-time data exfiltration with no user action beyond installation. It meets the blocking threshold.
This is a concrete install-time data-exfiltration chain with obfuscation and shell execution. It is malicious, not package-aligned behavior.
This is concrete, unconsented install-time collection and external exfiltration of sensitive host data. The package contains no legitimate implementation that would justify this behavior.
This is concrete, unconsented install-time reconnaissance and exfiltration rather than a package-aligned function. The environment guard narrows targeting but does not remove the maliciou...