Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 17:14 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms adxaa@1.0.0 as malicious (MAL-2026-14058): Malicious code in adxaa (npm)
Source inspection confirms an import-time, targeted browser-disruption payload. The lack of install hooks does not mitigate runtime protestware.
This is concrete import-time installation and manifest mutation of a different registry package, not a user-invoked update command. Absence of npm lifecycle hooks does not mitigate the ru...
This is concrete unconsented import-time mutation of a consumer project, directed at a package name different from the reviewed package. The documented updater claims it installs fca-nx,...
This is a concrete, automatically triggered remote-access payload with host fingerprinting and screenshot exfiltration. It is malicious, not an inert bundled artifact.