Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 22:50 UTC. Ordered by latest scan.
OpenSSF/OSV malware advisory MAL-2026-14277 blocks this version. The package's main entry index.js imports child_process at the top of the file and invokes spawn("powershell",...) as a to...
OpenSSF/OSV malware advisory MAL-2026-14275 blocks this version. package.json declares a postinstall hook running scripts/init.js, which chmod 0755's assets/thanks-amd64.elf and execFileS...
OpenSSF/OSV malware advisory MAL-2026-14277 blocks this version. The package's main entry index.js imports child_process at the top of the file and invokes spawn("powershell",...) as a to...
OpenSSF/OSV malware advisory MAL-2026-14273 blocks this version. The package advertises itself as a random-transaction generator but its exported getTransactions API triggers execution of...
OpenSSF/OSV malware advisory MAL-2026-14270 blocks this version. The package installs a global keyboard hook (keyboard.add_hotkey on ctrl+c), polls the system clipboard every 300ms via py...