Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 23:51 UTC. Ordered by latest scan.
The package has a concrete automatic install-time chain that writes broad AI-agent configuration and installs a command hook in the consumer project. This meets the install-hook-abuse blo...
The package embeds a reachable automatic account-mutation path controlled by a remote list. Its benign Node-version preinstall check does not mitigate that runtime behavior.
This is a concrete, remote-controlled, unconsented action on an authenticated user account. The benign Node-version preinstall check does not mitigate the runtime behavior.
The sole package source defines an automatic preinstall reverse shell, which is direct malicious install-hook behavior.