Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 13:19 UTC. Ordered by latest scan.
This is an active install-time DNS exfiltration path, not a configuration registry function. The encoded implementation and external endpoint support malicious intent.
This is an automatic, obfuscated DNS exfiltration path unrelated to an ABI library. It activates both at install time and import time without consent.
The package uses automatic install hooks to transmit host-identifying information to unrelated fixed external endpoints. This is concrete malicious data exfiltration behavior.
Automatic lifecycle hooks actively beacon local system metadata to fixed external endpoints. The behavior is concrete install-time data exfiltration, not normal package functionality.