Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:49 UTC. Ordered by latest scan.
The automatic lifecycle hook launches six unsolicited browser windows and detaches its process, creating disruptive behavior on installation. The README's self-description as a benign sca...
Inspected source proves automatic, concealed execution of a bundled encoded PowerShell command through a self-deleting script. This concrete behavior supports blocking independently of sc...
OpenSSF Malicious Packages via OSV confirms hardhat-init@2.21.0 as malicious (MAL-2026-17636): Malicious code in hardhat-init (npm)
OpenSSF Malicious Packages via OSV confirms @badzz88/baileys@8.6.0 as malicious (MAL-2026-17341): Malicious code in @badzz88/baileys (npm)
OpenSSF Malicious Packages via OSV confirms serpacksven1@1.0.6 as malicious (MAL-2026-17626): Malicious code in serpacksven1 (npm)