Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 10:23 UTC. Ordered by latest scan.
The published entrypoint contains active, targeted browser disruption behavior that is unrelated to a threshold compiler’s function. This supports a malicious protestware verdict and block.
The package entrypoint loads a heavily obfuscated module that invokes shell execution and includes network capability. This concrete, reachable behavior warrants blocking despite the exac...
The automatic lifecycle hook launches six unsolicited browser windows and detaches its process, creating disruptive behavior on installation. The README's self-description as a benign sca...
Inspected source proves automatic, concealed execution of a bundled encoded PowerShell command through a self-deleting script. This concrete behavior supports blocking independently of sc...