Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 14:42 UTC. Ordered by latest scan.
The lifecycle hook performs covert executable deployment and detached execution during installation. This is concrete malicious install-hook abuse.
The active executable performs credential and local-file collection followed by a network send. Its npm command name makes the behavior especially likely to be triggered through command c...
Automatic install-time host-identifier transmission to an external IP is a concrete data-exfiltration behavior. The duplicated import-time request reinforces that this is active behavior...
The preinstall hook unconditionally harvests hostname and username and sends them over HTTP during install, with errors silenced, while presenting the package as @waves/icons. Self-descri...