Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 02:26 UTC. Refreshes when new reports are published.
The install hook performs unrelated host-data collection, external-path mutation, and detached-process creation without user consent. These concrete install-time behaviors warrant blockin...
The delayed import-time network fetch and hidden remote-config write are concrete, nonessential attack behavior. No lifecycle hook is required because normal module use triggers it.
The package establishes a persistent system service during postinstall and hides the implementation with heavy obfuscation. This is concrete malicious install-time persistence.
The malicious actions are directly reachable from an npm postinstall hook and require no user invocation. They combine secret exfiltration, remote-controlled host scanning, and SSH persis...