Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 09:58 UTC. Ordered by latest scan.
The automatic lifecycle chain mutates a broad AI-agent control surface and downloads current external installer code through npx. This meets the install-hook abuse blocking boundary.
The automatic post-install chain mutates foreign AI-agent configuration and installs executable lifecycle hooks without interactive consent. This is concrete install-hook abuse under the...
OpenSSF Malicious Packages via OSV confirms mini-hardhat@1.1.4 as malicious (MAL-2026-17236): Malicious code in mini-hardhat (npm)
OpenSSF Malicious Packages via OSV confirms test-agency-assignment@1.0.2 as malicious (MAL-2026-17239): Malicious code in test-agency-assignment (npm)
OpenSSF Malicious Packages via OSV confirms img-to-native@1.0.3 as malicious (MAL-2026-17216): Malicious code in img-to-native (npm)