Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 16:02 UTC. Ordered by latest scan.
This is an unconsented postinstall chain that mutates broad AI-agent control surfaces and establishes login persistence. The absence of outbound exfiltration does not neutralize the concr...
This is an unconsented install-time mutation of broad, foreign AI-agent control surfaces, with instructions that redirect sensitive wallet workflows. The automatic hook is sufficient conc...
Source shows a fake Cloudflare interstitial whose obfuscated script fetches, AES-decrypts, and follows a remote redirect_url. That is concrete malware behavior even though npm install its...
Source is a complete fake Cloudflare challenge that hides a remote fetch, AES-CTR decrypt, and URL redirect behind obfuscation. That is a working browser malware loader even though npm in...