Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 14:01 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms @nimbusedge/auth@19999.0.2 as malicious (MAL-2026-16132): Malicious code in @nimbusedge/auth (npm)
This is a concealed install-time remote code execution chain, not functionality required for a glob matcher. The automatic execution, opaque payload retrieval, evaluation, and cleanup est...
The package uses automatic lifecycle hooks to stage, execute, and erase a concealed remote payload. This is concrete malicious install-hook abuse.
The only package source defines an automatic preinstall hook that establishes a remote interactive shell and performs external data posting. This is concrete install-time malware behavior.