Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 05:55 UTC. Ordered by latest scan.
The automatic install-time network fetch and forced replacement of shared executables are concrete, while the runtime embeds directives that control other AI agents' authentication and co...
The automatic postinstall hook mutates a foreign AI-agent control surface by globally installing Claude Code and persistently changes user startup and application files. This is concrete...
This is malicious install-hook abuse: an automatic lifecycle hook broadly alters foreign OpenCode/project state and global tooling, while runtime code reinforces the package's upgrade and...
This is concrete malicious install-hook abuse: an automatic lifecycle hook modifies consumer package-manager settings and broad AI-agent control surfaces while suppressing review and enco...