Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 16:15 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms 3layerdipstackvo9oet@0.1.4 as malicious (MAL-2026-14966): Malicious code in 3layerdipstackvo9oet (npm)
OpenSSF Malicious Packages via OSV confirms @hd-team/app-dnpkg-beta@1.0.20260808153500 as malicious (MAL-2026-14569): Malicious code in @hd-team/app-dnpkg-beta (npm)
Source inspection confirms unconsented install-time transmission of the host name to an external collection endpoint. The automatic hooks and self-dependency increase the supply-chain risk.
OpenSSF Malicious Packages via OSV confirms @fleetbo/svro@0.0.42 as malicious (MAL-2026-14586): Malicious code in @fleetbo/svro (npm)