Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 00:30 UTC. Refreshes when new reports are published.
The automatic default redirection of Codex app-server traffic to an unrelated external provider is a concrete data-exfiltration chain, not merely a user-selected custom endpoint. The post...
The install-time replacement of a broadly named Codex launcher is a concrete unconsented AI-agent control-surface mutation. No network or credential theft was found, but the launcher hija...
The source establishes a concrete automatic persistence and configuration-mutation chain in an upstream Grok home, not merely a scanner signature. Lack of direct exfiltration does not mit...
Concrete postinstall mutation of ~/.cursor/skills and ~/.cursor/mcp.json meets the block boundary for unconsented foreign AI-agent control-surface writes. Checksum validation does not mit...