Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 04:55 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms vuln-package@99.9.10 as malicious (MAL-2026-10212): Malicious code in vuln-package (npm)
Source inspection confirms automatic, full-screen delivery of remotely controlled external content on import. No install hook is needed for this malicious runtime behavior.
This package performs unverified install-time retrieval of executable and native-code payloads, then executes the retrieved binary. That is a concrete opaque remote-payload chain rather t...
OpenSSF Malicious Packages via OSV confirms ggk-happy@1.2.30 as malicious (MAL-2026-4789): Malicious code in ggk-happy (npm)