Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 08:22 UTC. Ordered by latest scan.
Automatic lifecycle execution performs unsolicited host and project reconnaissance and transmits it externally. The package's research claim does not remove this concrete install-time exf...
Automatic install-time host reconnaissance and covert transmission to hard-coded external endpoints are concrete malicious behavior. Error suppression and a DNS fallback reinforce the int...
The source implements deceptive process disguise, persistence, covert screen capture, and external transmission rather than the advertised DOM diagnostic function. These concrete behavior...
Automatic lifecycle execution combines local data collection with outbound transmission to unrelated collectors. This is malicious install-hook data exfiltration.