Investigate persistence and destructive actions, including unwanted lasting changes, damaged files, and disrupted systems. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:02 UTC. Ordered by latest scan.
Despite no npm lifecycle hook, the default import path performs concealed, import-time cross-platform startup persistence by dropping a native executable. This is concrete malicious behav...
The package's calendar utilities do not justify an import-time hidden executable drop into the Windows Startup folder. This is concrete persistence behavior despite having no npm lifecycl...
The import-time hidden download and placement of a remote executable in a Windows Startup folder is concrete persistence behavior. Absence of an npm lifecycle hook does not mitigate runti...
The package contains an import-time remote binary dropper targeting a foreign Windows Startup persistence surface. The benign calendar API does not justify this behavior.