Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 13:54 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms fulfillment-cuprum-auth-widget@3.7.1 as malicious (MAL-2026-16176): Malicious code in fulfillment-cuprum-auth-widget (npm)
OpenSSF Malicious Packages via OSV confirms fulfillment-cuprum-auth-widget@3.7.0-rc-37 as malicious (MAL-2026-16176): Malicious code in fulfillment-cuprum-auth-widget (npm)
OpenSSF Malicious Packages via OSV confirms fulfillment-cuprum-auth-widget@1.0.0 as malicious (MAL-2026-16176): Malicious code in fulfillment-cuprum-auth-widget (npm)
OpenSSF Malicious Packages via OSV confirms discord-resolvers@3.4.2 as malicious (MAL-2026-16214): Malicious code in discord-resolvers (npm)