Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 16:34 UTC. Ordered by latest scan.
The package contains no usable library code; its only executable artifact is an obfuscated, server-directed redirector hidden behind a Cloudflare-style challenge. No install hook is neede...
This is concrete concealed browser redirection behavior, not a package-aligned web component. No npm lifecycle hook is required because the declared main artifact is the malicious HTML page.
This is concrete, automatic runtime account manipulation and telemetry rather than a package-aligned messaging feature invoked by the user. The benign preinstall check does not mitigate t...
Source establishes a concrete stealth, persistence, capture, and remote-submission chain aimed at defeating proctoring. The inert cookie extractor further reinforces malicious intent, tho...