Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 23:36 UTC. Ordered by latest scan.
This is concrete import-time remote payload execution, not package-aligned telemetry. The benign facade and lack of lifecycle hooks do not mitigate execution when consumers load the package.
OpenSSF Malicious Packages via OSV confirms native-hello-plugin@1.2.0 as malicious (MAL-2026-13350): Malicious code in native-hello-plugin (npm)
This is a concrete import-time staged-payload execution chain unrelated to the declared template interface. The absence of lifecycle hooks does not mitigate execution on normal package use.
The benign exported API is a wrapper around automatic import-time remote binary execution. This is concrete malware behavior, not telemetry or a user-invoked optional setup path.