Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 05:50 UTC. Ordered by latest scan.
This is concrete, unconsented use of an authenticated third-party account combined with concealed targeting and host telemetry. The install hook itself is limited, but the runtime behavio...
This package contains a silent, automatic install-time telemetry beacon that inspects consumer project metadata and transmits it to a third party without an explicit user command. The ven...
The package has a concrete automatic postinstall persistence mechanism that mutates broad, foreign AI-agent control surfaces. Its injected instructions steer agents toward wallet and pass...
The automatic lifecycle hook makes broad, persistent changes to foreign AI-agent control surfaces and installs an additional global package. This meets the install-hook abuse boundary reg...