Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 20:24 UTC. Ordered by latest scan.
The package has a concrete, concealed install-time data-exfiltration path. The Sentry dynamic require is package-aligned and does not mitigate the lifecycle-hook behavior.
Source inspection confirms a concealed, automatic browser-redirection chain behind a security-verification lure. Absence of install hooks does not mitigate the delivered malicious runtime...
Direct source inspection confirms unconsented install-time remote beaconing and shell execution. The claimed PoC purpose does not remove the concrete behavior affecting every installer.
Direct source inspection confirms unconsented install-time network activity, not merely a static hint. No broader payload behavior was found, but the concrete lifecycle beacon warrants bl...