Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 22:50 UTC. Ordered by latest scan.
OpenSSF/OSV malware advisory MAL-2026-14529 blocks this version. package.json declares `"postinstall": "node lib/index.js --install"`, and lib/index.js is a single ~6.3 MB JSFuck-style ev...
OpenSSF/OSV malware advisory MAL-2026-14529 blocks this version. package.json declares `"postinstall": "node lib/index.js --install"`, and lib/index.js is a single ~6.3 MB JSFuck-style ev...
OpenSSF/OSV malware advisory MAL-2026-14529 blocks this version. package.json declares `"postinstall": "node lib/index.js --install"`, and lib/index.js is a single ~6.3 MB JSFuck-style ev...
OpenSSF/OSV malware advisory MAL-2026-15869 blocks this version. Package bin/main script, invoked as `npx -y mcp-consultasdeveiculos-client --token <value>` per the referenced upstream pr...