Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 00:24 UTC. Ordered by latest scan.
This is concrete, automatic, destructive mutation of a consumer project at install time, with build-time restoration of package-controlled files. The absence of installer exfiltration doe...
The package has a concrete automatic postinstall path that mutates several unrelated user-level AI-agent control surfaces. No self-dependency or exfiltration was needed to establish insta...
This is a concrete install-hook abuse chain: automatic lifecycle execution obtains and runs remote code, globally installs software, and persists fetched content. The isolated shared-agen...
The automatic postinstall chain modifies another package's launcher and renderer, then makes the modification self-healing and persistent across normal launches. This meets the install-ho...
OpenSSF Malicious Packages via OSV confirms server-authorized-cleanup@1.1.0 as malicious (MAL-2026-16079): Malicious code in server-authorized-cleanup (npm)