Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 02:38 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms @apexfdn/apex@1.0.1 as malicious (MAL-2026-10979): Malicious code in @apexfdn/apex (npm)
Direct source inspection confirms an install-time chain for configuration/secret exfiltration and attempted SSH persistence. This is concrete malicious behavior, not a library feature or...
OpenSSF Malicious Packages via OSV confirms @omniwatch-wick/cli@0.1.2 as malicious (MAL-2026-10486): Malicious code in @omniwatch-wick/cli (npm)
Source establishes a concrete, remotely controlled and unconsented account-action chain. The lifecycle hook is benign, but it does not mitigate the runtime behavior.