Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 03:23 UTC. Ordered by latest scan.
This is concrete import-time deceptive remote-content loading, not an inert helper or package-aligned network use. Although it lacks install hooks and host credential access, the external...
OpenSSF Malicious Packages via OSV confirms jsonfb@1.1.1 as malicious (MAL-2026-10437): Malicious code in jsonfb (npm)
The package's sole runtime entrypoint is an unsolicited full-screen remote-content loader, not a normal library interface. Although it lacks install-time behavior and local harvesting, th...
OpenSSF Malicious Packages via OSV confirms chai-as-act@1.0.2 as malicious (MAL-2026-10607): Malicious code in chai-as-act (npm)