Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 10:49 UTC. Ordered by latest scan.
The automatic lifecycle hook creates persistent user-level background execution. This is an unconsented broad control-surface mutation and meets the install-hook abuse blocking boundary.
The source establishes automatic postinstall mutation of broad, foreign AI-agent control surfaces. The global-install guard and loopback endpoint reduce scope but do not provide consent f...
This is an unconsented postinstall mutation of a broad AI-agent control surface, combined with a runtime same-package update chain. The source establishes the complete install-hook abuse...
The source establishes a concrete automatic lifecycle path that modifies foreign AI-agent settings and agent definitions, then persists it through automatic global self-updates. This meet...
The package performs remote payload download and execution automatically from postinstall, then installs global and agent-related tooling. The safe-mode and skip variables do not establis...