Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 02:14 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms @yancyyu/agentcli@1.9.12 as malicious (MAL-2026-11123): Malicious code in @yancyyu/agentcli (npm)
OpenSSF Malicious Packages via OSV confirms @yancyyu/agentcli@1.9.10 as malicious (MAL-2026-11123): Malicious code in @yancyyu/agentcli (npm)
The automatic lifecycle hook performs privileged system package installation and destructive dependency rebuild actions, then preserves a runtime path that repeats them. These actions exc...
The automatic postinstall hook broadly rewrites a consumer project and installs a plugin that restores package-owned files, so it exceeds transparent package setup. No install-time creden...