Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 17:34 UTC. Ordered by latest scan.
This is an unconsented install-time remote-payload chain that automatically invokes opaque AI-tool onboarding. The optional integrity check and process termination increase the risk.
This is an automatic lifecycle delivery chain for opaque native code from an unverified remote source, with TLS verification explicitly disabled. It creates a concrete install-time arbitr...
This is an unconsented postinstall mutation of broad foreign AI-agent control surfaces, with destructive synchronization and an installed agent-execution instruction set. It meets the ins...
The package has a concrete automatic postinstall path that modifies host software through package managers, including sudo, and repeats it at runtime. This is unsafe install-hook abuse ra...