Investigate persistence and destructive actions, including unwanted lasting changes, damaged files, and disrupted systems. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 09:34 UTC. Ordered by latest scan.
Source inspection confirms concrete import-time remote payload delivery and Startup-folder persistence, inconsistent with the documented calendar utility. This is malicious behavior, not...
The package contains a concealed import-time remote payload delivery and persistence chain unrelated to calendar utilities. This is concrete malware behavior.
This is concrete, unconsented persistence through import-time dropping of an embedded executable, unrelated to the stated package purpose.
This is concrete hidden persistence behavior unrelated to the stated utility package and activates merely on import. Absence of an npm lifecycle hook does not mitigate the import-time dro...