Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 19:07 UTC. Ordered by latest scan.
Direct source inspection confirms unconsented postinstall mutation of broad, foreign AI-agent configuration and permission surfaces. This meets the firewall block boundary regardless of t...
The postinstall hook concretely deletes foreign AI runtime packages during installation. Global-only scope and opt-outs reduce breadth but do not make the unconsented lifecycle mutation s...
The package performs unconsented postinstall mutation of broad foreign AI-agent control surfaces. This meets the firewall block boundary even though no install-time exfiltration was found.
Source confirms an unconsented postinstall mutation of multiple foreign AI-agent control surfaces. This meets the firewall block policy regardless of the installer’s lack of network activ...