Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:02 UTC. Ordered by latest scan.
The package entrypoint immediately evaluates obfuscated code with remote loader, network, and child-process indicators, supporting a malicious verdict despite the absence of install hooks...
The published entrypoint contains active, targeted browser disruption behavior that is unrelated to a threshold compiler’s function. This supports a malicious protestware verdict and block.
The package entrypoint loads a heavily obfuscated module that invokes shell execution and includes network capability. This concrete, reachable behavior warrants blocking despite the exac...
OpenSSF Malicious Packages via OSV confirms personio-pipeline-projen@1.171.31 as malicious (MAL-2026-17642): Malicious code in personio-pipeline-projen (npm)