Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 04:31 UTC. Ordered by latest scan.
This is concrete postinstall mutation of several foreign/global AI-agent control surfaces, meeting the blocking policy. The additional daemon autostart increases persistence risk.
This is concrete, unconsented postinstall mutation of broad foreign AI-agent control surfaces, which meets the publish-block policy. The skip flags and lack of lifecycle networking do not...
This is concrete, covert runtime abuse of an authenticated third-party service, not a normal package-aligned network operation. No install hook is required because it activates during ord...
Direct source inspection confirms an install-time rewrite of a foreign AI coding-agent package and UI dependency. This meets the blocking policy regardless of the package's stated brandin...