Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 21:42 UTC. Ordered by latest scan.
The package performs broad, automatic mutation of a consuming project and persists control over its entry files through an injected build plugin. Reviewer-directed prompt-injection langua...
The package performs unconsented privileged-capable system mutation from an automatic install hook and repeats it on ordinary execution. This is a concrete install-hook abuse path, not me...
This is an unconsented install-time mutation of broad consumer project and AI-agent control surfaces, with durable execution paths added to later installs and Git operations. The behavior...
This is concrete unconsented postinstall mutation of a broad AI-agent control surface. The lifecycle hook persists package-controlled commands and instructions globally, meeting the insta...