Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 23:11 UTC. Ordered by latest scan.
This is an automatic install-time remote payload execution chain with persistence and no cryptographic verification. The opaque executable is immediately authorized to perform further ins...
This is an unconsented postinstall mutation of broad foreign AI-agent control surfaces, amplified by a remote mutable payload source. It meets the install-hook abuse blocking policy.
The package automatically executes a mutable remote native payload during postinstall and delegates broad system and agent-tool setup to it. This is concrete install-hook abuse despite th...
Automatic lifecycle execution bypasses consent in non-interactive contexts and launches a concealed helper that builds and persists a background service outside the package. This is concr...
The claimed dry-run behavior contradicts the helper's actual default control flow. Automatic creation of a detached service and home-directory state during installation is concrete instal...