Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 21:10 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms titan-exchange-shared-permissions@99.9.9 as malicious (MAL-2026-13664): Malicious code in titan-exchange-shared-permissions (npm)
Source inspection confirms a disguised challenge page whose callback performs an obfuscated external redirect with query forwarding. Although it has no install hook, this is concrete mali...
OpenSSF Malicious Packages via OSV confirms agenthub-ai@0.20.3 as malicious (MAL-2026-13615): Malicious code in agenthub-ai (npm)
OpenSSF Malicious Packages via OSV confirms agenthub-ai@0.20.1 as malicious (MAL-2026-13615): Malicious code in agenthub-ai (npm)