Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 14:22 UTC. Ordered by latest scan.
The package contains concrete, stealthy postinstall mutation of the consuming project’s dependency manifest. No network exfiltration is needed for this install-hook supply-chain abuse to...
OpenSSF Malicious Packages via OSV confirms frenchworldcupwin@2.0.5 as malicious (MAL-2026-14318): Malicious code in frenchworldcupwin (npm)
This contains concrete, unconsented runtime account mutation and host-fingerprint exfiltration, not merely package-aligned WhatsApp functionality. The install hook is local-only but does...
The import-time payload combines host-data collection and outbound Axios submission with concealed detached process execution. The absence of lifecycle hooks limits the trigger to runtime...