Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 04:58 UTC. Ordered by latest scan.
This is an unconsented postinstall mutation of broad, foreign AI-agent control surfaces. The lack of network access in the installer does not remove the persistence and control-surface risk.
This is an unconsented postinstall mutation of broad AI-agent control surfaces, including persistent instructions and command hooks. The automatic lifecycle chain meets the publish-block...
This is an automatic install-time mutation of foreign AI-agent control surfaces across multiple products. Although scoped to global installs and using a loopback endpoint, it materially c...
The automatic postinstall hook mutates a broad set of foreign AI-agent control surfaces, meeting the install-control-surface block policy. No runtime self-dependency or install-time netwo...