Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 12:54 UTC. Ordered by latest scan.
Source establishes concrete stealth, persistence, proctoring-evasion, screen/UI capture, and automated AI-assisted cheating behavior. The benign postinstall hook does not mitigate the mal...
The package performs install-time delivery and registration of an unsigned native payload while explicitly evading platform security checks. The bundled checksum does not address the inte...
Source inspection confirms a concrete import-time global install and remote configuration chain unrelated to the advertised testing library. This is malicious dependency behavior.
The package performs a concealed import-time installation of a differently named package into the consuming project, controlled by a remote registry response. No lifecycle hook is needed...
This is concrete, remotely controlled, unconsented account mutation during normal package use. The harmless Node-version preinstall check does not mitigate the runtime behavior.