Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 22:28 UTC. Ordered by latest scan.
This is a concrete automatic install hook that retrieves and executes an unauthenticated native payload, then requests agent-hook installation. That combination is malicious install-hook...
This is concrete unconsented postinstall mutation of broad, foreign AI-agent control surfaces. The cross-platform fan-out and automatic installation meet the install-hook abuse blocking p...
The automatic lifecycle hook broadly changes AI-agent configuration and instruction directories across multiple vendors. This matches install-hook abuse even though no network exfiltratio...
This is an automatic, obfuscated install hook that downloads and executes unverified native code from a remote host. Its dependency-repair purpose does not remove the install-time remote-...
The package contains concrete, automatic install-time host mutation and network download behavior. Although the implementation is readable and no credential theft was found in the inspect...