Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 21:48 UTC. Ordered by latest scan.
This is concrete import-time execution of a bundled malicious native payload, not a package-aligned accelerator. No lifecycle hook is needed for the payload to activate when the advertise...
The package performs an undisclosed, automatic action on the user's authenticated WhatsApp account, concealed in an obfuscated policy module. Its install hook is not the attack vector, bu...
The import-time executable is concrete, unrelated to the package purpose, and contains explicit malware capabilities. No install hook is needed for impact because ordinary application imp...
The package executes an opaque, network-capable native binary during ordinary import and detaches it from the host process. The visible JavaScript functionality does not require that binary.