Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 22:18 UTC. Ordered by latest scan.
The package embeds a remote-controlled, automatic account-subscription action in its standard runtime connection path. Its benign lifecycle version check does not mitigate that concrete b...
The package contains concealed, automatic account manipulation and a remotely controlled target list. This is concrete malicious runtime behavior, not package-aligned setup.
The runtime socket contains a concrete, remotely controlled, unconsented action on the consumer's authenticated WhatsApp account. The benign Node-version preinstall check does not mitigat...
This is concrete unconsented install-time host data exfiltration to an external endpoint. The lifecycle trigger and callback are directly established by source inspection.