Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 12:09 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms chai-as-indexed@7.2.8 as malicious (MAL-2026-16293): Malicious code in chai-as-indexed (npm)
The runtime bundle hides a year check that throws an empty error after 2026 and aborts module initialization, which is a concrete protestware time bomb. No install hook or data theft was...
OpenSSF Malicious Packages via OSV confirms @nubjs/types@0.9.4 as malicious (MAL-2026-17186): Malicious code in @nubjs/types (npm)
The lifecycle hook performs broad AI-agent configuration mutation and automatic plugin installation. This is a concrete install-hook abuse chain, not an explicit user-invoked setup flow.
The main callable path reaches deliberately concealed dynamically constructed code. This is concrete active malicious behavior, even though the concealed payload's final actions are not s...