Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 21:05 UTC. Ordered by latest scan.
Automatic postinstall behavior changes foreign AI-agent configuration and broad host settings while fetching and executing a remote binary. This meets the install-hook abuse blocking thre...
The package has a concrete automatic postinstall path that mutates broad third-party AI-agent control surfaces and performs substantial host bootstrap actions. This meets the install-hook...
This is concrete, unconsented postinstall mutation of broad AI-agent control surfaces combined with persistence. It meets the install-hook-abuse blocking policy regardless of the package'...
This is a deceptive, obfuscated browser redirector rather than a legitimate npm library. It has no install hook, but the delivered runtime behavior is concrete malicious traffic routing.