Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 21:44 UTC. Ordered by latest scan.
This is concrete, unconsented install-time system profiling and data exfiltration to an unrelated hard-coded endpoint. The empty runtime export does not justify the lifecycle behavior.
This is concrete, unconsented install-time collection and exfiltration of local host and account identity data. The lifecycle trigger and outbound HTTP behavior establish a malicious supp...
This is unconsented install-time collection and exfiltration of host and user identity data to an unrelated external IP address. The empty runtime module provides no legitimate package fu...
The import-time loader combines remote payload execution, detached process creation, and self-removal. These behaviors are concrete malicious execution, even though npm lifecycle hooks ar...