Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 17:34 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms kartyk-github-oidc-test-pkg@1.0.2 as malicious (MAL-2026-16244): Malicious code in kartyk-github-oidc-test-pkg (npm)
This is a concrete import-triggered remote code execution and persistence mechanism, not a package-aligned utility. The absence of an install hook does not mitigate execution on ordinary...
The published main file immediately exfiltrates browser cookies to webhook.site. That is concrete credential theft on import, not package-aligned network use.
src/index.js is an obfuscated Ethereum-backed dropper that evals and spawn-executes recovered code on plugin import, while the README, types, and repository metadata impersonate a Tailwin...