Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 18:16 UTC. Ordered by latest scan.
The lifecycle hook performs unverified remote payload retrieval and broad user-environment package installation automatically. These actions create a concrete install-time code-execution...
The automatic install hook deletes external user binaries and performs persistent machine tracking with remote transmission. This is concrete destructive behavior and data exfiltration un...
The package performs unconsented privileged operating-system package installation from postinstall and retries it on CLI startup. This is a concrete host-mutation attack surface despite n...
This is an automatic install-hook supply-chain mutation that imports an unverified external native payload into a consumer dependency. The explicit plugin commands do not mitigate the sep...
The automatic lifecycle hook broadly mutates foreign AI-agent control surfaces and registers package-owned command callbacks. This meets the install-hook abuse blocking policy despite no...