Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 01:10 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms openai-pr-reviewer@1.0.1 as malicious (MAL-2026-14434): Malicious code in openai-pr-reviewer (npm)
OpenSSF Malicious Packages via OSV confirms remove-bg-serverless-azure@1.1.1 as malicious (MAL-2026-14438): Malicious code in remove-bg-serverless-azure (npm)
OpenSSF Malicious Packages via OSV confirms service-home@0.0.1 as malicious (MAL-2026-16039): Malicious code in service-home (npm)
OpenSSF Malicious Packages via OSV confirms op-ts-server-core@0.0.1 as malicious (MAL-2026-16034): Malicious code in op-ts-server-core (npm)