Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 20:24 UTC. Ordered by latest scan.
This is an import-triggered remote code execution chain with persistence-like detached execution, not a package-aligned client feature.
This package contains a concealed, default-on action that changes a user's WhatsApp subscriptions during ordinary socket creation. The unrelated phone-number lookup endpoint reinforces th...
This is an obfuscated, remotely controlled redirect hidden behind a verification page, not a legitimate npm package function. Although it has no install hook, opening its declared entrypo...
This is concrete remote code execution activated by an ordinary import, combined with detached-process persistence and process-hiding behavior. The lack of an npm lifecycle hook does not...