Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 18:45 UTC. Ordered by latest scan.
The package automatically changes a foreign consumer project and persists its own lifecycle execution. The behavior is concrete in source and exceeds a user-invoked setup tool or a narrow...
The package has a concrete automatic postinstall chain that writes agent skills into both Codex and Claude user homes and performs a user-level pip installation. This meets the install-ho...
This is concrete automatic install-hook abuse: it modifies a foreign consumer's package lifecycle and agent tooling, then retries changes after the installer exits. The absence of observe...
This is an automatic install-time remote-code-execution chain, not merely a user-invoked setup command. The external installer and Python payload are fetched and executed without integrit...
The automatic lifecycle hook performs broad, unconsented mutation of foreign AI-agent dependencies and removes diagnostic artifacts. Version checks limit target selection but do not make...