Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 15:39 UTC. Ordered by latest scan.
The automatic lifecycle hook broadly mutates foreign AI-agent control surfaces and registers package-owned command callbacks. This meets the install-hook abuse blocking policy despite no...
The install hook mutates broad, foreign AI-agent control surfaces and accepts remotely fetched instruction content. This is concrete unconsented install-hook abuse.
The source establishes a complete automatic postinstall chain that overwrites executables owned by @openai/codex. Backup and hash checks do not mitigate the unconsented replacement of the...
This is unconsented install-time host mutation with automatic privileged package-manager execution, and it persists as a retrying runtime behavior. It is not required for ordinary depende...