Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 07:02 UTC. Ordered by latest scan.
This is a concrete unconsented postinstall mutation of broad foreign AI-agent control surfaces. Under the firewall policy it warrants blocking even without observed exfiltration.
This is concrete install-time mutation of a foreign, broad AI-agent control surface. The installed wildcard handler has authority to deny Claude tool calls.
The behavior is directly reachable from postinstall and writes broad agent instruction surfaces after a remote fetch. Explicit setup paths do not mitigate the automatic lifecycle trigger.
This is a concrete unconsented postinstall mutation of a foreign AI-agent control surface, followed by package-supplied instructions that can solicit credentials and transfer project arti...