Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 01:53 UTC. Ordered by latest scan.
The unconditional postinstall download of an unsigned executable from an unrelated C2-named host is concrete malicious payload staging, despite no execution call in the inspected source.
OpenSSF Malicious Packages via OSV confirms requestor-util@99.9.1 as malicious (MAL-2026-10965): Malicious code in requestor-util (npm)
The Node import path contains an unconditional, unrelated detached-process launch and database connector invocation. This is concrete unauthorized runtime behavior, not an inert scanner s...
The concealed remote control of unsolicited authenticated WhatsApp actions is concrete malicious runtime behavior. The lifecycle alias mutation adds further unrequested install-time modif...