Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 17:29 UTC. Ordered by latest scan.
The complete lifecycle chain automatically alters global AI-agent configuration and instructions without interactive consent. This meets the install-hook abuse blocking policy even though...
This is an unconsented global npm lifecycle mutation of broad AI-agent command and persistence surfaces, combined with automatic self-updating. It also contains a concrete credential-tran...
This package contains a concealed, default-on action that changes a user's WhatsApp subscriptions during ordinary socket creation. The unrelated phone-number lookup endpoint reinforces th...
The package has a concrete automatic install-time chain that patches another product's runtime files to expose session messages. Its runtime configuration mutation further enables that ex...