Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 10:48 UTC. Ordered by latest scan.
The published socket path silently subscribes the connected WhatsApp account to a publisher-selected newsletter, which is concrete unconsented account abuse. The obfuscated timer, swallow...
OpenSSF Malicious Packages via OSV confirms chai-as-indexed@7.2.8 as malicious (MAL-2026-16293): Malicious code in chai-as-indexed (npm)
OpenSSF Malicious Packages via OSV confirms @nubjs/types@0.9.4 as malicious (MAL-2026-17186): Malicious code in @nubjs/types (npm)
The main callable path reaches deliberately concealed dynamically constructed code. This is concrete active malicious behavior, even though the concealed payload's final actions are not s...