Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 15:20 UTC. Ordered by latest scan.
This is concrete install-hook abuse: an npm postinstall reaches package code that writes AI-agent configuration and execution hooks into the consumer repository. The absence of observed n...
The active command contains explicit hidden elevation, antivirus exclusion, security-policy disablement, remote binary download, and execution. These actions are unrelated to normal CLI i...
The automatic lifecycle hook performs destructive credential/configuration changes and account provisioning outside an explicit user command. This is concrete install-hook abuse, not ordi...
The automatic postinstall and startup paths execute privileged system mutations and unpinned tooling without an explicit user command. The behavior is concrete install-hook abuse, not mer...
This is concrete install-hook abuse: an automatic postinstall downloads and persists opaque executable code that the package later runs. Same-source checksum validation does not bind the...