Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 19:51 UTC. Ordered by latest scan.
Postinstall unconditionally installs a native binary and mutates config.toml in the official Grok home while the package identity is @kingingwang, not @xai-official. That is unconsented i...
The automatic postinstall hook performs concrete, broad mutations of foreign AI-agent dependencies and obscures them by deleting source maps. No network exfiltration was needed to establi...
The automatic lifecycle hook makes broad, persistent changes to third-party AI-agent controls and installs a Codex plugin. This is concrete install-hook abuse under the stated policy.
The postinstall path unconditionally launches a global skills install into home directories shared by AI agents, with the yes flags set and stdio piped. That is unconsented mutation of a...