Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 16:46 UTC. Ordered by latest scan.
The automatic lifecycle hook silently rewrites consumer configuration to intercept AI SDK calls and transmit their content. This meets the install-hook abuse policy for a foreign AI-agent...
This is a concrete install-time mutation of a consumer AI integration that enables collection and external reporting of LLM content. The behavior is automatic rather than an explicit user...
The package contains concrete automatic install-time data transmission rather than only user-invoked networking. The lifecycle path is transparent but unconsented and suppresses its netwo...
The package executes automatic system-package installation, including sudo attempts, from its npm postinstall hook and repeats it at CLI startup. This is a concrete install-hook abuse rat...
The published entrypoints contain concrete, import-time protestware that disables page interaction and fetches looping audio for targeted visitors. That is unconsented attack behavior in...