Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 14:34 UTC. Ordered by latest scan.
This is an unverified, mutable remote-binary execution chain in a postinstall hook, with an environment-controlled source and quarantine removal. That is concrete install-hook abuse rathe...
The automatic postinstall chain mutates foreign AI-agent control surfaces and establishes login persistence. This is concrete install-hook abuse under the launcher isolation policy.
The package performs a concrete destructive action automatically at install time against consumer dependencies. This establishes malicious install-hook abuse regardless of the otherwise o...
This is a concrete automatic postinstall mutation of broad, foreign AI-agent control surfaces. The guarded scope and lack of observed exfiltration do not remove the unconsented persistent...