Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 14:40 UTC. Ordered by latest scan.
The package contains concealed, automatic account manipulation and a remotely controlled target list. This is concrete malicious runtime behavior, not package-aligned setup.
The runtime socket contains a concrete, remotely controlled, unconsented action on the consumer's authenticated WhatsApp account. The benign Node-version preinstall check does not mitigat...
OpenSSF Malicious Packages via OSV confirms codebuff-cli@1.1.3 as malicious (MAL-2026-4533): Malicious code in codebuff-cli (npm)
OpenSSF Malicious Packages via OSV confirms codebuff-cli@1.0.10 as malicious (MAL-2026-4533): Malicious code in codebuff-cli (npm)