Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 20:15 UTC. Ordered by latest scan.
The complete lifecycle path automatically and silently modifies global instruction files for three unrelated AI-agent tools, then injects directives that influence future sessions. This i...
The automatic postinstall hook mutates a foreign AI-agent control surface and installed dependencies, then can execute another install script with inherited environment variables. This is...
The automatic postinstall hook performs broad dependency replacement and removes debugging artifacts. That is concrete install-hook abuse, regardless of the absence of a confirmed externa...
This is a concrete install-hook abuse chain affecting the consumer's files and Git remote. The editor settings are benign-looking, but they do not justify destructive deletion, commit, an...