Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 19:29 UTC. Ordered by latest scan.
The package has a concrete automatic postinstall chain that mutates a broad AI-agent control surface and registers persistent session-start execution. This meets the install-hook abuse bl...
This is a concrete automatic install-time persistence chain combined with silent system dependency installation. Its Windows-only scope and local watchdog target do not make the unconsent...
This is a concrete postinstall chain that installs a native payload and uses it to alter third-party AI-agent hooks. The behavior meets the install-hook abuse block policy despite package...
The package contains deliberate, top-level, targeted browser disruption in both published entrypoints. Although it has no install hook, its import-time protestware behavior is concrete an...