Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 05:55 UTC. Ordered by latest scan.
The automatic postinstall mutation targets broad, foreign AI-agent control surfaces and is coupled with user-level dependency installation. This meets the install-hook abuse blocking boun...
This is an unconsented postinstall mutation of a foreign AI-agent control surface, combined with persistent user-environment and launcher writes. The package therefore meets the install-h...
The package has a concrete, automatic postinstall mutation of a global Claude Code skill directory and forcibly replaces its contents. This meets the install-control-surface blocking poli...
The automatic postinstall chain mutates Claude Code's control surface and installs an external plugin during npm installation. This is concrete unconsented install-hook abuse.