Investigate persistence and destructive actions, including unwanted lasting changes, damaged files, and disrupted systems. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 08:48 UTC. Ordered by latest scan.
The postinstall hook deletes consumer-project data without a package-aligned need, then executes a downloaded binary. This is concrete destructive install-time behavior, not ordinary wrap...
The undocumented, import-time hidden launch and directory watch establish a concrete covert execution chain. The lack of a network sink does not remove the local execution and staging risk.
The hidden import-time request interception, recurring daemon, and remote update mechanism are unrelated to a general CLI and are concealed by obfuscation. This is concrete malicious pers...
The automatic lifecycle hook performs privileged, hidden, logon-triggered persistence and starts the persisted task. This is concrete install-time persistence rather than an explicit user...