Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 08:31 UTC. Ordered by latest scan.
This is unconsented postinstall mutation of a broad AI-agent control surface. The lifecycle hook persists package-controlled commands and instructions in the user's global Claude Code con...
The automatic lifecycle hook mutates a foreign global AI-agent installation and persistent user configuration. This is a concrete install-time control-surface risk even though no credenti...
The automatic postinstall hook broadly mutates foreign AI-agent configuration and establishes a self-updating execution path through local-mcp@latest and remote binaries. This is concrete...
The package uses an automatic npm lifecycle hook to mutate several foreign global AI-agent skill directories and to obtain content from the network. This is a concrete unconsented control...