Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 23:33 UTC. Ordered by latest scan.
OpenSSF/OSV malware advisory MAL-2026-15671 blocks this version. On npm install, the package's preinstall hook (package.json scripts.preinstall = `node index.js`) executes index.js, which...
OpenSSF/OSV malware advisory MAL-2026-15645 blocks this version. LPM AI assessed this version as suspicious; the assessments disagree. kisama-js@0.4.8 ships an obfuscated index.js that ru...
OpenSSF/OSV malware advisory MAL-2026-15835 blocks this version. The package presents itself as a Tailwind CSS color/service-worker helper, but the `daisypick/plugin` export reads a URL f...
OpenSSF/OSV malware advisory MAL-2026-15674 blocks this version. This package presents itself as a "System binary configuration tool" — that is its entire manifest description, with keywo...
OpenSSF/OSV malware advisory MAL-2026-15645 blocks this version. LPM AI assessed this version as suspicious; the assessments disagree. kisama-js@0.4.8 ships an obfuscated index.js that ru...