Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 01:06 UTC. Ordered by latest scan.
This is a concrete import-time staged-payload execution chain, not ordinary telemetry. The larger telemetry module independently contains the same payload-download-and-launch capability w...
The package contains a real, import-time, targeted page-disruption payload rather than merely suspicious primitives. Lack of install hooks does not mitigate runtime harm to downstream bro...
This is a concealed staged malware loader, not calendar parsing: it dynamically evaluates hidden code, writes a remote executable, and executes it. Absence of lifecycle hooks does not mit...
This is concrete, automatic abuse of a connected third-party account rather than a package-aligned API exposed for caller use. The benign preinstall hook does not mitigate the runtime pay...