Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 01:30 UTC. Ordered by latest scan.
Direct source inspection confirms unconsented postinstall mutation of a consumer project’s broad AI-agent control surface and persistent Git configuration. The overwrite guard does not mi...
This meets the block boundary: an npm postinstall mutates a foreign host project’s AI/MCP configuration and activates a Git hook. Lack of a confirmed network exfiltration path does not re...
The lifecycle script performs unconsented postinstall mutation of the foreign, user-wide Claude Code hook surface. Its conditional binary lookup does not make the automatic persistent hoo...
Direct inspection confirms an unconditional postinstall write to a foreign, user-wide AI-agent MCP configuration. This meets the install-time agent-control-hijack block boundary.