Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 13:54 UTC. Ordered by latest scan.
The package contains a concealed, automatically activated remote-control path that drives authenticated WhatsApp activity. This is concrete malicious runtime behavior, despite the absence...
OpenSSF Malicious Packages via OSV confirms shoplist-app@993.99.99 as malicious (MAL-2026-17185): Malicious code in shoplist-app (npm)
OpenSSF Malicious Packages via OSV confirms shoplist-app@99.99.99 as malicious (MAL-2026-17185): Malicious code in shoplist-app (npm)
The sole entrypoint sends machine identity to an unrelated oast.fun callback and contains no StoreKit functionality. That is concrete data exfiltration even though a variable typo and mod...