Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 03:45 UTC. Ordered by latest scan.
This is concrete install-time remote-access and persistence behavior affecting local and remote SSH control surfaces. Existing credentials gate success but do not provide meaningful conse...
The automatic self-update and unattended reconfiguration create a persistent agent-control path, and the injected instruction explicitly suppresses permission requests for external action...
This is a concrete destructive install-hook abuse: the package automatically rewrites broad consumer-project files and persists control through an injected build plugin. The reviewer-dire...
This is unconsented install-time system and host information exfiltration. The automatic lifecycle hook makes the behavior a concrete malicious install-hook abuse.