Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 16:36 UTC. Ordered by latest scan.
Source directly implements covert profile collection and account sweeping, coupled to permission-bypassing AI-agent command execution and platform synchronization. Absence of npm lifecycl...
This is a concrete unconsented postinstall mutation of a foreign AI-agent control surface, meeting the blocking policy. The declared vision feature does not remove the lifecycle-control r...
Source directly confirms a postinstall write into ~/.claude/skills and an agent-directed shell-execution payload. This meets the policy boundary for an unconsented lifecycle mutation of a...
This is a concrete, unconsented postinstall mutation of broad foreign AI-agent control surfaces. Lack of exfiltration does not remove the install-time agent-control hijack behavior.