Investigate persistence and destructive actions, including unwanted lasting changes, damaged files, and disrupted systems. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 09:34 UTC. Ordered by latest scan.
This is concrete destructive browser behavior hidden inside an ostensibly lightweight embedding component. It is reachable during normal component use and lacks transparent documentation...
This is an intentionally obscured browser denial-of-service payload that alters and locks a host page when deployed. The absence of installation hooks limits the trigger but does not neut...
The package performs a concrete destructive credential action automatically at install time. The native binary is opaque, and no installation need justifies clearing an existing user's au...
The package hides a remotely controlled kill switch in a photo-frame component and destroys the consumer page when its remote licence decision is negative. There is no install-time execut...