Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 13:54 UTC. Ordered by latest scan.
Direct source inspection confirms an unconsented `postinstall` write to a consumer-owned Claude Code hook configuration with wildcard interception. Under the stated install-control-surfac...
Source inspection confirms a concrete postinstall chain that writes package and remotely fetched content into ~/.claude/skills. Under the firewall policy, this warrants blocking regardles...
The lifecycle hook concretely writes AI-agent rule files into the consumer project during `npm install`. The non-overwrite guard and lack of network activity do not remove the unconsented...
The source confirms unconsented postinstall mutation of a global AI-agent extension/control surface and automatic installation of unrelated extensions. Although no exfiltration or destruc...