Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 19:03 UTC. Ordered by latest scan.
The package contains a concealed import-time dependency activation that is unrelated to the documented SDK and deliberately suppresses errors. Although the payload is not bundled here, th...
The package contains concrete, unconsented runtime account manipulation controlled by a remote endpoint. Its benign Node-version preinstall check does not mitigate that behavior.
OpenSSF Malicious Packages via OSV confirms baileys-mbuilder@4.7.0-lts as malicious (MAL-2026-14529): Malicious code in baileys-mbuilder (npm)
OpenSSF Malicious Packages via OSV confirms parallely@10.0.4 as malicious (MAL-2026-11143): Malicious code in parallely (npm)