Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 05:55 UTC. Ordered by latest scan.
The manifest establishes a concrete automatic destructive action against foreign project dependencies. This is malicious install-hook abuse, not a package-aligned setup step.
This is an automatic install-time remote-agent deployment chain unrelated to ULID generation. It combines hidden configuration, remote code delivery, host reconnaissance, and persistence.
The package has a concrete automatic postinstall path that broadly changes host project AI-agent configuration and installs an enforcement hook. This meets the install-hook abuse boundary...
The automatic postinstall broadens a package installation into persistent global AI-agent configuration mutation. The installed content includes instructions for privileged account actions.