Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 00:07 UTC. Ordered by latest scan.
The package has no install hook, but its normal runtime path performs broad, remote-updatable AI-agent control-surface mutation and executes a detached downloaded native runner. This is a...
The documented postinstall path automatically installs hooks across existing Claude Code/Codex environments, an unconsented foreign AI-agent control-surface mutation. Disclosure, opt-out...
Source confirms unconsented postinstall mutation of broad foreign AI-agent control surfaces. This meets the firewall block boundary despite the absence of observed network exfiltration. P...
The package has a concrete npm postinstall path that can mutate foreign Claude control files without affirmative consent. This meets the install-control-surface block policy despite the f...