Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 13:36 UTC. Ordered by latest scan.
Source inspection confirms automatic disclosure of machine information to a fixed external recipient. The package's security-research claims do not establish authorization for this instal...
Inspected source proves unconsented install-time mutation of a foreign, global AI-agent control surface. This meets the blocking policy even though the commands are Telora-related and no...
The automatic global-install chain activates foreign AI-client configuration without a consent step, meeting the blocking policy for install-time agent control-surface mutation. Package-a...
The user-wide fallback makes this an automatic mutation of a broad AI-agent control surface, rather than setup confined to package-owned extension state. This meets the supplied blocking...