Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 12:06 UTC. Ordered by latest scan.
The package performs automatic, broad consumer-project and AI-agent configuration changes during postinstall, then persists itself in the consumer's own lifecycle script. This meets the p...
The UMD entrypoint is intentionally obfuscated and dynamically evaluates generated code. This is concrete opaque runtime execution in the package's normal import path.
The package performs broad, privileged host mutation from automatic npm lifecycle hooks. This is concrete install-hook abuse, not a user-invoked setup action.
The install-time hook performs broad host package installation rather than limiting itself to package-local setup. The behavior is activated automatically by npm installation and can invo...
This package contains an automatic, environment-gated remote payload downloader and Windows executable launcher. Its install-time behavior is unrelated to its declared utility functionali...