Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 23:37 UTC. Ordered by latest scan.
OpenSSF/OSV malware advisory MAL-2026-6358 blocks this version. babel.config.cjs contains a heavily obfuscated (obfuscator.io-style) IIFE appended after a legitimate @babel/preset-env blo...
OpenSSF/OSV malware advisory MAL-2026-14504 blocks this version. The package was found to contain malicious code or consuming dependency that contains malicious code
OpenSSF/OSV malware advisory MAL-2026-14505 blocks this version. The package was found to contain malicious code or consuming dependency that contains malicious code
OpenSSF/OSV malware advisory MAL-2026-14503 blocks this version. The package was found to contain malicious code or consuming dependency that contains malicious code
OpenSSF/OSV malware advisory MAL-2026-6223 blocks this version. The package is published as 'mjs-eslint' but its description, file layout (big.js, big.mjs), and source are a verbatim copy...