Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 01:54 UTC. Ordered by latest scan.
The verified postinstall chain changes Claude and Codex user-level control surfaces without an explicit user setup action. That concrete install-hook behavior meets the publish-block poli...
This package has a concrete automatic postinstall path that persistently modifies user-level AI-agent configuration and hooks. The global-install guard does not provide explicit user cons...
This is a concrete automatic postinstall mutation of broad, foreign Codex and Claude agent configuration surfaces. The documented notice does not convert lifecycle execution into explicit...
This is an unconsented postinstall mutation of global AI-agent control surfaces, including destructive pruning of prior content. The behavior meets the install-hook abuse blocking boundar...