Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 07:50 UTC. Ordered by latest scan.
This is a concrete install-hook supply-chain risk: mutable remote executable content and unpinned user-wide Python packages are installed automatically. No credential theft was found, but...
The package uses postinstall to persist an evaluated command in multiple user shell configuration files. This automatic mutation of shell control files is a concrete install-hook abuse de...
The automatic lifecycle hook persists a new CI workflow in consumer repositories and causes future network reporting to an external registry. This is unconsented install-time project muta...
The automatic postinstall executes unpinned remote code and uses it to register hooks in a foreign AI-agent environment. This is concrete install-hook abuse, not merely an explicit user-i...
This is an automatic install-time remote-code-execution chain with deliberate detached execution. The remote payload is opaque to the package snapshot and has Node module access.