Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 14:35 UTC. Ordered by latest scan.
Source proves automatic, unconsented account mutation directed by a remote channel list, with muting that suppresses notifications. This concrete attack supports blocking independently of...
Source proves automatic, remotely directed account manipulation through the active socket entrypoint. The benign lifecycle and media-processing findings do not explain or neutralize this...
Source inspection establishes concealed, automatic account actions directed by a remote channel list. This is concrete unauthorized account manipulation, supporting a malicious verdict in...
OpenSSF Malicious Packages via OSV confirms @smwebserver/static@99.9.1 as malicious (MAL-2026-17456): Malicious code in @smwebserver/static (npm)
OpenSSF Malicious Packages via OSV confirms xcvrenzcompany@2.0.0 as malicious (MAL-2026-17452): Malicious code in xcvrenzcompany (npm)