Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 10:19 UTC. Ordered by latest scan.
Source inspection confirms a concrete postinstall chain that overwrites multiple consumer-project AI-agent instruction locations and runs a broad sync command. This meets the blocking pol...
Source inspection confirms a concrete npm postinstall control-surface mutation, not merely scanner similarity. This meets the block boundary even though no credential exfiltration or netw...
This is a concrete, unconsented postinstall mutation of foreign and broad AI-agent control surfaces. Documentation and an opt-out do not eliminate the automatic lifecycle behavior.
Direct source inspection confirms broad Claude Code installation, execution, shim replacement, and binary/source modification during npm postinstall. This meets the block boundary for unc...