Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 22:44 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms @agenthub-ai/agent@0.14.1 as malicious (MAL-2026-12312): Malicious code in @agenthub-ai/agent (npm)
OpenSSF Malicious Packages via OSV confirms @whalent/agent@0.3.298 as malicious (MAL-2026-10721): Malicious code in @whalent/agent (npm)
OpenSSF Malicious Packages via OSV confirms @whalent/agent@0.3.296 as malicious (MAL-2026-10721): Malicious code in @whalent/agent (npm)
OpenSSF Malicious Packages via OSV confirms @whalent/agent@0.3.297 as malicious (MAL-2026-10721): Malicious code in @whalent/agent (npm)