Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 18:50 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms bs58-15@6.0.1 as malicious (MAL-2026-13964): Malicious code in bs58-15 (npm)
The package contains a guarded but real postinstall path that performs privileged database administration against an embedded remote endpoint. This exceeds a UI theme library's expected b...
The malicious remote-access configuration executes automatically at install time and materially weakens host authentication and visibility. It is not merely an installer primitive or an e...
OpenSSF Malicious Packages via OSV confirms @dreamguyxeon/baileyx@4.0.0 as malicious (MAL-2026-13930): Malicious code in @dreamguyxeon/baileyx (npm)