Investigate persistence and destructive actions, including unwanted lasting changes, damaged files, and disrupted systems. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 08:48 UTC. Ordered by latest scan.
The undocumented, import-time hidden launch and directory watch establish a concrete covert execution chain. The lack of a network sink does not remove the local execution and staging risk.
This is concealed remote-controlled account mutation in the default runtime path, not a requested library feature. The benign Node-version preinstall check does not mitigate it.
The package has no npm lifecycle hook, but its declared main entrypoint performs unconsented browser-side persistence and ships an obfuscated remote loader. This is concrete malicious beh...
This is a remotely controlled, broad destructive operation disguised as cache cleanup. Its explicit invocation requirement reduces automatic exposure but does not make the behavior safe o...