Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 09:24 UTC. Ordered by latest scan.
The package is an obfuscated, remotely directed browser redirector presented as a security challenge. This is concrete deceptive traffic-routing behavior, not a package-aligned application.
The package actively implements concealed, challenge-gated remote redirection in its only payload. Its opaque implementation and lack of legitimate package behavior support blocking it as...
The package performs automatic postinstall mutation of a consumer Git hook and arranges future command execution. The checkout guard does not remove the unconsented lifecycle persistence.
The automatic postinstall path concretely overwrites existing AI-agent skill files across multiple foreign tools. Under the lifecycle control-surface policy, this is blockable install-hoo...