Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 05:11 UTC. Ordered by latest scan.
The inspected code establishes automatic, noninteractive consumer-project and AI-agent plugin mutation during postinstall, with detached persistence of reconciliation. This exceeds transp...
The automatic postinstall mutation targets broad, foreign AI-agent control surfaces and changes how host agents handle tasks. This meets the install-hook abuse blocking boundary despite t...
The package contains a concrete automatic install hook that runs a package manager against an external relative directory. The browser bundle findings do not mitigate this install-time mu...
The automatic lifecycle hook performs unconsented global AI-agent tooling and persistent user-environment mutations. This meets the install-hook abuse blocking boundary even though no cre...
This is a concrete install-hook abuse chain: automatic installation mutates a consumer project, changes its agent control surface, and persists through the consumer postinstall script. Th...