Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 17:07 UTC. Ordered by latest scan.
The automatic global installation of Anthropic's Claude Code from this unrelated package is a concrete unconsented postinstall mutation of a foreign AI-agent control surface. This meets t...
A covert, encoded prompt is wired into an automatic agent-control path and directs disclosure of sensitive conversational context. No install hook is involved, but the runtime behavior is...
This is a concrete unconsented postinstall mutation of broad foreign AI-agent control surfaces, including approval escalation and command hooks. It meets the firewall block boundary regar...
Source confirms an npm lifecycle hook installs and activates a package-controlled plugin in the unrelated global Herdr environment. This meets the install-time foreign AI-agent control-su...