Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 12:47 UTC. Ordered by latest scan.
Source confirms a concrete postinstall chain that persists hooks/extensions across third-party AI-agent environments and relays agent activity. This meets the block policy regardless of t...
Source confirms an unconsented postinstall chain that modifies both Codex-style and Claude agent configuration and installs a blocking lifecycle hook. This meets the firewall block bounda...
This is concrete, unconsented postinstall mutation of broad foreign AI-agent control surfaces with persistent lifecycle execution. The absence of install-time exfiltration does not mitiga...
This is an unconsented postinstall mutation of foreign AI-agent control surfaces through an unverified remote payload. The source directly establishes the installation and execution chain.