Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 15:02 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms fulfillment-cuprum-auth-widget@3.7.2 as malicious (MAL-2026-16176): Malicious code in fulfillment-cuprum-auth-widget (npm)
OpenSSF Malicious Packages via OSV confirms meraz-project-tracker@1.0.0 as malicious (MAL-2026-16161): Malicious code in meraz-project-tracker (npm)
The package's automatic postinstall makes privileged host-level software changes and its runtime path repeats the behavior. No exfiltration was confirmed, but the unconsented lifecycle mu...
The install hook automatically performs remote SSH key persistence and starts background services. This is concrete unconsented install-time behavior, not merely a user-invoked SSH utility.
The package performs broad, automatic mutations of a consumer project and installs a plugin that continually restores package-controlled source. This concrete install-hook persistence war...