Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 03:23 UTC. Refreshes when new reports are published.
This is concrete install-time delivery and persistence of a native executable with explicit security-control bypass behavior. The bundled checksum provides integrity only relative to the...
The advertised server utility embeds an undisclosed global install and stealthy background process launch to a remote API. Although it is runtime-triggered rather than npm lifecycle-trigg...
The source documents and implements an install-time unsigned native payload delivery chain designed to avoid OS security warnings. Bundled checksum validation does not negate the intentio...
The package embeds a concealed, cryptographically gated decrypt-and-spawn chain in its primary Mutex implementation. This is concrete malicious runtime behavior, not an unused static prim...
Direct source inspection confirms both silent install-time data exfiltration and deliberate payment-recipient redirection. These are concrete malicious behaviors, not merely suspicious pr...