Investigate persistence and destructive actions, including unwanted lasting changes, damaged files, and disrupted systems. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:49 UTC. Ordered by latest scan.
Despite no npm lifecycle hook, the default import path performs concealed, import-time cross-platform startup persistence by dropping a native executable. This is concrete malicious behav...
The package's calendar utilities do not justify an import-time hidden executable drop into the Windows Startup folder. This is concrete persistence behavior despite having no npm lifecycl...
The import-time hidden download and placement of a remote executable in a Windows Startup folder is concrete persistence behavior. Absence of an npm lifecycle hook does not mitigate runti...
The package contains an import-time remote binary dropper targeting a foreign Windows Startup persistence surface. The benign calendar API does not justify this behavior.