Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 07:26 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms z-deno-truth-bwhlsz@2.0.0 as malicious (MAL-2026-16470): Malicious code in z-deno-truth-bwhlsz (npm)
The package has no product behavior beyond an install hook that phones home host identity to webhook.site. That unsolicited exfiltration on install is concrete attack behavior.
OpenSSF Malicious Packages via OSV confirms ubiquiti-agents-link-mcp@0.2.1 as malicious (MAL-2026-16409): Malicious code in ubiquiti-agents-link-mcp (npm)
OpenSSF Malicious Packages via OSV confirms caphsmgiwy@1.0.0 as malicious (MAL-2026-16447): Malicious code in caphsmgiwy (npm)