Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 12:11 UTC. Ordered by latest scan.
The source establishes an unconsented postinstall chain that mutates foreign AI-agent configs and installs recurring commands. This meets the firewall block boundary despite global-instal...
The automatic postinstall mutates a foreign Claude-related AI-agent surface and deletes files from ~/.claude; this meets the block boundary. The unchecked executable download adds further...
Concrete postinstall code mutates global Claude and Codex skill roots and installs instructions that accept injected work. This meets the firewall block threshold regardless of the absenc...
The lifecycle chain concretely performs broad agent-control and hook persistence in the consuming project. Although no exfiltration was found, this meets the blocking policy for unconsent...