Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 21:18 UTC. Ordered by latest scan.
The package has a concrete automatic postinstall chain that changes user-wide Claude settings to capture and export session content. This meets the install-hook abuse policy for a malicio...
The install-time hook contains concrete remote-shell behavior, not a package-aligned setup action. This is malicious install-hook abuse.
The sole lifecycle script implements an install-time reverse shell and sends its output externally. This is concrete malicious behavior, not package setup.
The package performs unconsented install-time mutation of a broad AI-agent control surface by installing a separate global Claude Code package, alongside persistent shell and launcher cha...