Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 13:52 UTC. Ordered by latest scan.
The source implements stealth, watchdog persistence, foreground capture, and external submission as one active workflow. Although installation itself does not activate the launcher, the c...
This is concealed, automatic host-data exfiltration through DNS during installation, unrelated to the stated Solana library function. The behavior is concrete malicious install-time data...
Automatic lifecycle execution combines local data collection with outbound transmission to unrelated collectors. This is malicious install-hook data exfiltration.
Automatic lifecycle execution collects sensitive local and build-environment data and sends it to unrelated external hosts. This is concrete malicious install-time exfiltration.