Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 06:28 UTC. Ordered by latest scan.
This package contains concrete, unconsented mutations of a user's WhatsApp subscriptions and message content, plus a reachable shell-injection flaw. These behaviors are unrelated to ordin...
The confirmed install-time mutation of consumer files and existing AI-agent configuration is a concrete unconsented control-surface change. No exfiltration was needed to establish the ins...
This is unconsented install-time mutation of a consumer project and its future lifecycle behavior, with detached reconciliation to continue the chain. The CI guard and reduced mode do not...
This is deliberate, concealed, user-unconsented account manipulation on the normal runtime path. The harmless version-check install hook does not mitigate the runtime behavior.