Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 11:25 UTC. Ordered by latest scan.
The lifecycle script performs a global foreign AI-agent installation and persistent shell mutation without requiring an explicit user setup command. This meets the install-control-surface...
The automatic lifecycle hook mutates consumer AI-agent control surfaces and project metadata without an explicit user setup action. This meets the install-hook abuse blocking policy even...
Automatic install-time deletion, compilation, and attempted privileged system software installation create a concrete unsafe install-hook attack surface. The behavior warrants blocking ev...
The automatic postinstall hook silently mutates foreign AI-agent control surfaces, meeting the install-hook abuse blocking policy. The unrestricted MCP request path adds a concrete condit...
This is concrete unconsented postinstall mutation of foreign AI-agent control surfaces. The absence of observed credential theft does not neutralize the install-hook abuse.