Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 18:55 UTC. Ordered by latest scan.
The package performs an unconsented external runtime installation during postinstall, creating a supply-chain execution path outside npm's declared dependency set. The pinned version and...
This is an automatic remote-native-code execution chain with no independent payload authentication. The installer also weakens macOS execution protections for that remote payload.
This package performs unconsented install-time host mutation through privileged package-manager commands and repeats it at runtime. Its additional credential harvesting and network use ma...
The bridge combines deliberate evasion with an unrestricted AI-agent launcher, and the distributed code is intentionally obscured. The absence of a consumer lifecycle hook limits installa...
The package contains a concrete automatic postinstall chain that overwrites another product's UI files. This meets the install-control-surface blocking rule even though no credential thef...