Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 22:10 UTC. Ordered by latest scan.
The automatic lifecycle hook performs broad global AI-agent configuration changes rather than limiting setup to an explicit command or package-owned location. This meets the install-contr...
This is an unconsented postinstall mutation of a foreign AI-agent executable surface. The package transparently performs the replacement, but it supplies opaque native payloads that take...
The automatic postinstall hook mutates global Claude and Codex configuration and registers a lifecycle command outside the consumer project. This is concrete unconsented install-time AI-a...
The package uses an automatic npm lifecycle hook to alter several unrelated AI-agent instruction surfaces without a user command or consent. This meets the install-time AI-agent control-s...