Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 07:08 UTC. Ordered by latest scan.
This is a typosquatting package with an automatic lifecycle hook that writes and replaces executables in a foreign AI CLI home directory. The identity mismatch and unconsented control-sur...
The install-time hook executes remote code and changes global tooling and AI-skill state by default. This creates a concrete, unconsented supply-chain execution path.
This is an unconsented postinstall mutation of a foreign AI-agent control surface that deliberately removes a safety reminder. The local API client does not offset the install-time attack...
This package contains a complete automatic install-time chain for secret exfiltration and remote shell access. The behavior is malicious and requires blocking.