Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 13:14 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms kartyk-github-token-pkg@1.0.3 as malicious (MAL-2026-16246): Malicious code in kartyk-github-token-pkg (npm)
This package creates a concrete automatic supply-chain payload path by accepting and deploying an opaque remote native binary without certificate or integrity verification. The lifecycle...
This package performs persistent SSH-access setup and background service startup from postinstall rather than an explicit user action. That is concrete unconsented install-hook abuse, eve...
OpenSSF Malicious Packages via OSV confirms kartyk-github-oidc-test-pkg@1.0.1 as malicious (MAL-2026-16244): Malicious code in kartyk-github-oidc-test-pkg (npm)