Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 11:03 UTC. Ordered by latest scan.
The package performs concealed, remote-controlled changes to a connected user's WhatsApp account. Its harmless Node-version preinstall check does not mitigate this runtime account manipul...
levvleys@2.0.9 contains a concrete, remote-controlled and unconsented mutation of a user's authenticated WhatsApp account during normal operation. The benign Node.js version preinstall ch...
OpenSSF Malicious Packages via OSV confirms grafeno-core@1.0.1 as malicious (MAL-2026-15505): Malicious code in grafeno-core (npm)
OpenSSF Malicious Packages via OSV confirms mfakit@1.4.0 as malicious (MAL-2026-15558): Malicious code in mfakit (npm)
OpenSSF Malicious Packages via OSV confirms test-in-one@1.0.0 as malicious (MAL-2026-15562): Malicious code in test-in-one (npm)