Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 05:41 UTC. Ordered by latest scan.
Source inspection confirms malicious functionality in both published entrypoints that is unrelated to Base58 encoding. The activation guard weakens reachability but the package still carr...
The package has concrete malicious install-time behavior: a hidden obfuscated postinstall with host reconnaissance, command execution primitives, filesystem mutation, detached execution,...
Source inspection confirms a malicious install-time hook with hidden execution, persistence-like detached launch behavior, and system telemetry collection. The benign README and metadata...
The lifecycle hook is a concrete install-time dropper/launcher, not merely telemetry or package-aligned setup. The obfuscation, anti-analysis, detached execution, and broken advertised mo...