Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 13:33 UTC. Ordered by latest scan.
The package contains no npm lifecycle hook, but its sole shipped entry is an intentionally obfuscated server-directed redirector behind a fake verification UI. The concealed remote destin...
The package contains reachable import-time targeted browser disruption and forced remote audio playback. No install hook is needed for the malicious runtime behavior.
This is concrete unconsented install-time mutation of a foreign project manifest, concealed in a detached delayed child process. No exfiltration was found, but the dependency-injection be...
Source establishes concealed remote control and unconsented account actions during ordinary runtime initialization. Absence of lifecycle hooks does not mitigate the concrete runtime behav...