Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 03:25 UTC. Refreshes when new reports are published.
This is concrete malicious install-time behavior: a hidden privileged account, exposed RDP listener, stealth filesystem changes, and Windows-service impersonation. The absence of observed...
This is a concrete stealth anti-proctor and assessment-capture tool, not a benign diagnostic utility. The harmful runtime chain is user-triggered rather than install-time, but is sufficie...
This is concrete, unconsented install-time persistence. The absence of observed install-time exfiltration does not remove the risk of automatic background execution.
This is a concrete, unconsented install-time remote-access and stealth-persistence chain, not a package-aligned installer. Source contains no compensating user-command gate beyond the ele...
This is an unconsented install-time remote-access persistence chain, not a user-invoked administrative tool. The lack of a JavaScript exfiltration client does not mitigate the automatic h...