Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 01:26 UTC. Refreshes when new reports are published.
The install-time replacement of a broadly named Codex launcher is a concrete unconsented AI-agent control-surface mutation. No network or credential theft was found, but the launcher hija...
The source establishes a concrete automatic persistence and configuration-mutation chain in an upstream Grok home, not merely a scanner signature. Lack of direct exfiltration does not mit...
Concrete postinstall mutation of ~/.cursor/skills and ~/.cursor/mcp.json meets the block boundary for unconsented foreign AI-agent control-surface writes. Checksum validation does not mit...
Direct source inspection confirms unconsented postinstall mutation of global Claude and Codex controls, including executable lifecycle configuration. This meets the blocking policy regard...