Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 11:47 UTC. Ordered by latest scan.
This is active, import-triggered secret harvesting and exfiltration to an unrelated fixed endpoint. The behavior is concrete and requires blocking publication.
This is concrete automatic credential harvesting and data exfiltration during installation, concealed by heavy obfuscation. It is unrelated to a legitimate dotenv preflight check.
The import-time daemon and remote Function execution form an active remote-code-execution path. The cryptographic check authenticates the operator payload rather than constraining its cap...
OpenSSF Malicious Packages via OSV confirms mini-hardhat@1.1.4 as malicious (MAL-2026-17236): Malicious code in mini-hardhat (npm)