Investigate persistence and destructive actions, including unwanted lasting changes, damaged files, and disrupted systems. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 08:08 UTC. Ordered by latest scan.
The postinstall hook deletes consumer-project data without a package-aligned need, then executes a downloaded binary. This is concrete destructive install-time behavior, not ordinary wrap...
The undocumented, import-time hidden launch and directory watch establish a concrete covert execution chain. The lack of a network sink does not remove the local execution and staging risk.
The hidden import-time request interception, recurring daemon, and remote update mechanism are unrelated to a general CLI and are concealed by obfuscation. This is concrete malicious pers...
The automatic lifecycle hook performs privileged, hidden, logon-triggered persistence and starts the persisted task. This is concrete install-time persistence rather than an explicit user...