Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 19:19 UTC. Ordered by latest scan.
The launcher, overlay, screen grabber, and browser-cookie decryptor are concrete stealth and credential-theft behavior under a false package description. Install does not auto-start them,...
This is an active, obfuscated install-time metadata exfiltration path. It has no necessary relationship to a global-header component.
The published socket path silently subscribes the connected WhatsApp account to a publisher-selected newsletter, which is concrete unconsented account abuse. The obfuscated timer, swallow...
The published entrypoint automatically hooks every local DevTools page and sends captured page and editor text, with an embedded key, to a hardcoded third-party worker while certificate c...