Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 08:31 UTC. Ordered by latest scan.
The package has a concrete automatic install path that broadly modifies consumer AI-agent configuration and explicitly suppresses review of its generated files. This meets the install-hoo...
This is a lifecycle bootstrapper for a remote unsigned native payload that deliberately bypasses operating-system download protections and persists it in user launch surfaces. The behavio...
The automatic postinstall globally changes the consumer environment by installing a separate AI agent, rather than merely preparing this package. Combined with default auto-approved agent...
The automatic global installation of a separate AI-agent CLI and persistent user configuration mutation are concrete install-hook abuse. No secret exfiltration was found, but the unconsen...
The package automatically harvests environment data during installation and uses an obfuscated network command. Its runtime self-dependency selects a different release, making this a mali...