Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 21:42 UTC. Ordered by latest scan.
This is an unconsented postinstall mutation of a broad AI-agent control surface, with deletion and external MCP registration. The automatic global-install path is concrete in the publishe...
The package has a concrete automatic lifecycle chain that modifies a foreign global agent configuration and installs a persistent startup plugin. Source inspection found no need for remot...
The package performs concrete, unconsented persistence and broad AI-agent control-surface changes, then provides an automatic self-update path to another lifecycle-enabled release. These...
The lifecycle path performs broad, automatic project-level AI-agent configuration and establishes later hook execution. The absence of observed secret theft does not remove this concrete...