Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 04:08 UTC. Ordered by latest scan.
This is an unconsented install-time mutation of broad, foreign AI-agent control surfaces, with persistent instruction content and destructive synchronization. It meets the install-hook ab...
This is a concrete unconsented postinstall agent-integration action performed by an opaque downloaded executable. Digest verification limits replacement risk but does not make the automat...
The package has an automatic install hook that fetches and executes opaque native code and then automatically refreshes AI-agent integrations. Hash verification does not establish the saf...
This is an unconsented postinstall mutation of both a consumer project and an existing user-level AI-agent control surface. The automatic registration is concrete and sufficient for a pub...