Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 02:23 UTC. Ordered by latest scan.
This is an automatic install-time credential-harvesting and reverse-shell payload, reinforced by explicit typosquat metadata. It warrants blocking.
This is an automatic install-time credential-exfiltration and reverse-shell chain, not a user-invoked administrative feature. The hard-coded external server and typosquat metadata further...
This is a concealed, remotely controlled browser redirect packaged as an npm entry point. The lack of install hooks does not mitigate the delivered phishing or malware-routing behavior.
OpenSSF Malicious Packages via OSV confirms @quantixfinance/token@1.0.0 as malicious (MAL-2026-15854): Malicious code in @quantixfinance/token (npm)