Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 11:13 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms @hrmony/kit@1.99.0 as malicious (MAL-2026-17263): Malicious code in @hrmony/kit (npm)
This is active, automatic credential and secret exfiltration from the package entrypoint. The behavior is unrelated to account management and has a concrete external transmission sink.
This is active, automatic credential and secret harvesting followed by transfer to an unrelated external endpoint. The behavior is concrete data theft, not a package-aligned capability.
This is active credential and secret exfiltration triggered by importing the package. The absence of an install hook does not mitigate the concrete import-time attack.