Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 11:30 UTC. Ordered by latest scan.
The package deliberately impersonates Node to intercept dependency lifecycle execution and performs unconsented local and browser side effects before forwarding the command. Its lack of i...
OpenSSF Malicious Packages via OSV confirms tailwindcss-3d-styles@1.2.4 as malicious (MAL-2026-15905): Malicious code in tailwindcss-3d-styles (npm)
OpenSSF Malicious Packages via OSV confirms easypanel-core@1.0.0 as malicious (MAL-2026-15897): Malicious code in easypanel-core (npm)
OpenSSF Malicious Packages via OSV confirms easypanel-docker@1.0.0 as malicious (MAL-2026-15899): Malicious code in easypanel-docker (npm)
OpenSSF Malicious Packages via OSV confirms easypanel-client@1.0.0 as malicious (MAL-2026-15896): Malicious code in easypanel-client (npm)