Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 09:17 UTC. Ordered by latest scan.
Direct inspection confirms automatic postinstall mutation of foreign AI-agent configuration and agent files. The global-only guard limits scope but does not provide separate consent for t...
The package contains a concrete automatic install-time chain that modifies consumer lifecycle scripts and AI-agent control surfaces, then persists and replays those changes. This meets th...
The reviewed source establishes an automatic postinstall chain that mutates a foreign project and user-wide AI-agent configuration, with detached persistence of its changes. That concrete...
This is unconsented postinstall mutation of broad, foreign AI-agent control surfaces, combined with instructions that autonomously redirect agent work and a self-update path that repeats...
The automatic postinstall hook broadly modifies the consumer repository’s AI-agent control surface and configures a package-owned MCP command. This meets the policy for malicious install-...