Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 14:00 UTC. Ordered by latest scan.
The automatic postinstall path mutates Windows Terminal profiles used to launch Claude and Codex and creates elevated persistence. These actions occur without an explicit user setup command.
This is concrete unconsented postinstall persistence plus mutation of a foreign AI-agent control surface. The absence of observed remote exfiltration does not mitigate the lifecycle attac...
The source confirms an automatic postinstall overwrite of a foreign Pi coding-agent host, expanding its extension API. This is a concrete unconsented AI-agent control-surface mutation.
The package's declared feature does not justify silently installing and activating code in the separate DeepSeek Harness control plane during npm postinstall. This meets the blocking poli...