Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 11:30 UTC. Ordered by latest scan.
The preinstall hook unconditionally harvests hostname and username and sends them over HTTP during install, with errors silenced, while presenting the package as @waves/icons. Self-descri...
The main module is an import-time loader that stealthily executes a fixed disguised executable path after waiting for a companion dependency to place it. That behavior is unrelated to the...
The published entrypoint itself launches a concealed executable from a fixed user-profile path, independent of the documented binary runner API. That import-time hidden spawn is concrete...
The import-triggered, heavily obfuscated command execution and outbound request are concrete malicious behavior. Absence of an install hook does not remove the runtime attack surface.