Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 21:02 UTC. Ordered by latest scan.
The package performs automatic install-time network retrieval and execution of an opaque binary, then automatically installs agent skills. This creates a concrete unconsented AI-agent con...
This is unconsented postinstall mutation of broad AI-agent control surfaces, with an opaque native binary that contains a safeguard-bypass flag. The package meets the publish-block thresh...
The automatic postinstall executes opaque native code specifically to install agent hooks, including code obtained without integrity verification. This is a concrete install-hook abuse pa...
This is an automatic lifecycle mutation of a foreign AI-agent executable path using opaque bundled binaries. The installer’s backup and rollback features do not remove the unconsented exe...