Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 15:15 UTC. Ordered by latest scan.
Source confirms an npm lifecycle hook installs and activates a package-controlled plugin in the unrelated global Herdr environment. This meets the install-time foreign AI-agent control-su...
This is a concrete install-time AI-agent control-surface hijack, not merely an explicit setup command. The lifecycle hook suppresses output while creating persistent cross-agent configura...
The source establishes a concrete install-time chain from npm postinstall to foreign Herdr plugin deployment and detached execution. This meets the install-control-surface block condition...
The lifecycle hook performs unconsented global installation of a foreign AI-agent CLI, which is a concrete install-time control-surface mutation. Benign desktop-shell functionality does n...