Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 07:30 UTC. Ordered by latest scan.
This is a concrete unconsented npm postinstall mutation of broad, foreign AI-agent control surfaces. Under the stated policy, that requires a block regardless of the package-aligned servi...
The install hook concretely writes package-controlled AI-agent instructions into foreign global agent directories. This meets the blocking policy for unconsented postinstall mutation of a...
Direct inspection confirms the lifecycle script writes package-controlled instructions into existing ~/.claude and ~/.codex installations. This meets the blocking policy regardless of the...
Direct inspection confirms the postinstall drop into ~/.claude and ~/.codex, not merely scanner inference. This meets the firewall block boundary for unconsented postinstall mutation of b...