Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 14:35 UTC. Ordered by latest scan.
The package contains an automatic lifecycle hook that implements remote interactive command execution. This is malicious install-hook abuse.
The automatic install hook broadly mutates a consumer project's AI-agent configuration and package-manager behavior, then installs reviewer-suppressing rules. This is concrete install-hoo...
The package uses postinstall to persist unrestricted Claude Code command hooks in a user-level configuration file. This meets the install-hook abuse blocking boundary.
The package contains a preinstall hook that executes a shell-based external request. This is concrete install-hook abuse with no package functionality supporting it.