Investigate persistence and destructive actions, including unwanted lasting changes, damaged files, and disrupted systems. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 10:23 UTC. Ordered by latest scan.
This is concrete import-time malware, not a user-invoked library feature. It downloads remote code, executes it hidden, and establishes persistence.
This is concrete unconsented install-time mutation of a consumer repository that persists as a GitHub workflow and reports repository metadata externally. The behavior is not required for...
This is concrete import-time malware behavior: covert remote payload execution and multi-method Windows persistence unrelated to Discord MFA. The absence of an npm lifecycle hook does not...
The package contains a concrete import-time denial-of-service path aimed at CI and sandbox environments, plus concealed dynamic loading. These behaviors are not required for the documente...