Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 23:32 UTC. Ordered by latest scan.
OpenSSF/OSV malware advisory MAL-2026-14252 blocks this version. npm-wold@1.1.1 declares a postinstall script (`node dist/config.js`) that, on `npm install`, issues an HTTPS GET to the ha...
OpenSSF/OSV malware advisory MAL-2026-14252 blocks this version. npm-wold@1.1.1 declares a postinstall script (`node dist/config.js`) that, on `npm install`, issues an HTTPS GET to the ha...
OpenSSF/OSV malware advisory MAL-2026-14250 blocks this version. index.js stores a remote URL and a `curl -sL -o` command as numeric char-code arrays and reconstructs them at runtime with...
OpenSSF/OSV malware advisory MAL-2026-14241 blocks this version. LPM AI assessed this version as suspicious; the assessments disagree. Package is an openly-advertised DDoS/booter toolkit...
OpenSSF/OSV malware advisory MAL-2026-14240 blocks this version. bin/dxr.js unconditionally requires the external npm package 'deathoffather-project' pinned to the mutable 'latest' tag an...