Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 03:25 UTC. Refreshes when new reports are published.
The package's declared feature does not justify silently installing and activating code in the separate DeepSeek Harness control plane during npm postinstall. This meets the blocking poli...
The package has a concrete lifecycle-triggered AI-agent control-surface mutation chain, including remote-sourced content. This meets the block boundary despite no observed credential exfi...
The automatic postinstall mutates broad, foreign AI-agent control surfaces and can introduce remotely refreshed instructions. This meets the block boundary regardless of otherwise legitim...
This is concrete unconsented postinstall mutation of foreign/broad AI-agent control surfaces, including remotely refreshed instruction content. It meets the firewall block boundary despit...