Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 02:23 UTC. Refreshes when new reports are published.
The package embeds an undisclosed external script and an obfuscated fetch-plus-new-Function loader activated by opening its page. This is a concrete remote code execution surface, not mer...
The package performs concealed import-time remote payload execution unrelated to its declared text-helper functionality. This is concrete malware behavior.
This is concrete install-time malware, not a package-aligned diagnostic feature: it establishes remote command execution, persistence, and internal credential/service reconnaissance.
The package’s main functionality and runtime security controls appear package-aligned, but the unconditional postinstall remote-script execution is a concrete, unconsented install-time RC...
The package hides a remote payload downloader and detached interpreter execution behind its advertised API. No lifecycle hook is needed for this consumer-triggered malicious execution path.