Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 02:59 UTC. Ordered by latest scan.
This is concrete, unconsented install-time data exfiltration with redundant network channels. The package's research label does not neutralize the automatic behavior.
The automatic lifecycle hooks activate host and environment reconnaissance and transmit the results to an unrelated external Telegram recipient. The behavior is concrete install-time data...
This is concrete install-time host reconnaissance and outbound exfiltration to an unrelated Telegram recipient. The automatic lifecycle hook makes the behavior unconsented.
The source implements deceptive process disguise, persistence, covert screen capture, and external transmission rather than the advertised DOM diagnostic function. These concrete behavior...