Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 01:13 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms cbc97b7a@1.1788006723.0 as malicious (MAL-2026-15878): Malicious code in cbc97b7a (npm)
OpenSSF Malicious Packages via OSV confirms cbc97b7a@1.1787999998.0 as malicious (MAL-2026-15878): Malicious code in cbc97b7a (npm)
The package is a disguised browser redirect loader rather than a usable npm library. Its obfuscation, remotely supplied encrypted destination, and challenge-gated automatic navigation est...
OpenSSF Malicious Packages via OSV confirms vitest-cli-dev@10.0.7 as malicious (MAL-2026-15870): Malicious code in vitest-cli-dev (npm)
This package contains an automatic, environment-gated remote payload downloader and Windows executable launcher. Its install-time behavior is unrelated to its declared utility functionali...