Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 15:06 UTC. Ordered by latest scan.
This is a concrete automatic credential-exfiltration chain unrelated to wallet balance checking. Its install hook and runtime API both activate the scanner, so it should be blocked.
The package’s import path launches a detached binary whose embedded commands implement backdoor, payload-execution, and credential-harvesting functionality. This is concrete malicious beh...
The code implements a concealed, persistent page-locking payload with no evident legitimate package interface. Absence of installation hooks and network activity limits the impact but doe...
OpenSSF Malicious Packages via OSV confirms fieldbase-webapplication-buildtools@99.99.99 as malicious (MAL-2026-15847): Malicious code in fieldbase-webapplication-buildtools (npm)