Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 03:42 UTC. Ordered by latest scan.
The package contains a concrete postinstall path that alters several third-party AI-agent skill directories and installs instructions that influence later agent actions. This meets the po...
This is a complete unconsented postinstall chain that mutates a consumer AI import path and transmits intercepted LLM content remotely. The behavior meets the install-hook abuse policy fo...
This is a concrete install-hook abuse chain: automatic lifecycle execution obtains and runs remote code, globally installs software, and persists fetched content. The isolated shared-agen...
The install hook automatically and silently modifies both Claude and Codex global configuration, registering executable package code. This meets the blocking policy for unconsented lifecy...