Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 04:20 UTC. Ordered by latest scan.
The package performs automatic install-time remote shell execution and installs a second executable component outside the reviewed artifact. This is an unconsented install-hook code-loadi...
The package automatically provisions and mutates AI-agent control surfaces in the consuming project and user environment. Its self-dependency range increases lifecycle-chain risk, so this...
The package performs unconsented remote payload execution during postinstall and retrieves mutable remote agent content. This is concrete install-hook abuse with a remote code execution p...
This is concrete, unconsented install-time collection and exfiltration of credentials and project data. The harmless research framing does not match the implemented behavior.