Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 13:54 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms @quantixfinance/api@1.0.0 as malicious (MAL-2026-15848): Malicious code in @quantixfinance/api (npm)
The automatic lifecycle hook performs privileged host configuration and service activation. This is concrete install-hook abuse, despite CI and non-interactive guards.
This is an unconsented postinstall mutation of broad and foreign AI-agent control surfaces. The lifecycle hook and recursive overwrite behavior establish concrete install-hook abuse despi...
The package contains concealed, automatic, and remotely controlled actions that alter the user's WhatsApp account. This is concrete unconsented behavior, not normal media or socket functi...