Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 13:14 UTC. Ordered by latest scan.
This package contains an active preinstall payload intended to run when a dependency-confusion target installs it. The automatic collection and network action make this a blockable instal...
The package contains an automatic preinstall hook that collects and sends local identifiers. This is concrete install-hook abuse, not required behavior for the declared module.
The package uses an automatic install hook to execute a remotely fetched shell installer and configure a separate AI-related tool in the user's environment. This is an unconsented lifecyc...
The automatic, forced user-scope agent-skill installation is concrete install-hook abuse. Its global scope and behavior-changing instructions meet the blocking policy even without evidenc...