Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 06:35 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms taskforge-9xv@1.3.0 as malicious (MAL-2026-15914): Malicious code in taskforge-9xv (npm)
The inspected source establishes an automatic install-time chain that mutates consumer and user AI-agent configuration. This meets the policy boundary for unconsented lifecycle control-su...
The package deliberately impersonates Node to intercept dependency lifecycle execution and performs unconsented local and browser side effects before forwarding the command. Its lack of i...
The opaque runtime is not aligned with the minimal package metadata and deliberately hides an AI-message steering path. Although it has no install hook, the concrete user-invoked behavior...