Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 03:05 UTC. Ordered by latest scan.
The package performs unconsented system package installation during postinstall and normal startup, then automatically globally reinstalls itself from npm. These are concrete install-hook...
This is an unconsented install-time remote code execution chain. The signature check does not mitigate the package author's ability to deliver arbitrary code after publication.
This is a concrete install-hook payload delivery chain: an opaque native executable is automatically downloaded from a fixed host with TLS verification disabled, extracted, and enabled fo...
The package performs unconsented remote script execution and external tool configuration from a postinstall hook. This is concrete install-hook abuse, even though the snapshot contains no...