Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 11:30 UTC. Ordered by latest scan.
Direct source inspection confirms an automatic install hook that executes remote code and persists it through shell profiles and cron. The benign runtime export does not mitigate this con...
This is a concrete install-time remote-code-execution and persistence chain unrelated to the package's exported utilities. The package should be blocked.
The confirmed preinstall hook performs concealed remote code execution from an unreviewable payload. The harmless-looking runtime stub does not mitigate this install-time behavior.
The package contains a confirmed automatic install-time remote-code-execution chain. Its minimal runtime code does not justify or constrain that behavior.