Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 00:46 UTC. Ordered by latest scan.
This package executes remotely supplied scripts during an unconsented npm lifecycle hook and installs an external runtime outside the package. Its CLI also implements detached automatic r...
The automatic lifecycle chain executes mutable remote code and changes global tooling and skills without consent. This is concrete install-hook abuse, not merely user-invoked setup.
This is a concrete, unconsented install-hook abuse chain that broadly mutates and persistently controls consumer application files. No install-time exfiltration was found, but the destruc...
This is an automatic install-time remote code delivery chain with disabled TLS validation and no integrity verification. The downloaded native payload is opaque to the package review and...