Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 13:10 UTC. Ordered by latest scan.
This package contains an active preinstall payload intended to run when a dependency-confusion target installs it. The automatic collection and network action make this a blockable instal...
The active entrypoint implements unsolicited browser credential and data collection followed by transmission to an unrelated external endpoint. This is concrete credential and data exfilt...
Importing the package runs an obfuscated loader that shells out through execSync and prepares host and username collection plus an axios send. That is concrete remote command execution hi...
Import of the published entrypoint is a dropper: it decrypts a concealed payload with a hardcoded key and writes an executable while deleting the staging file. The image-conversion API do...