Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 09:34 UTC. Ordered by latest scan.
The package's declared CommonJS entrypoint resolves to a bundle containing active, delayed browser disruption and unsolicited audio playback for a targeted audience. This supports a malic...
The package’s published import entry contains targeted browser disruption that disables interaction and plays remote audio. This is active behavior in the shipped bundle, so the evidence...
Inspected source confirms targeted, delayed browser disruption in the package's browser bundle. This is concrete protestware behavior, so the package should be blocked.
The published browser bundle includes targeted page disruption and unwanted external audio playback. This is concrete malicious protestware behavior, so publication should be blocked.