Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 04:58 UTC. Ordered by latest scan.
The automatic lifecycle hook mutates a broad, foreign AI-agent control surface and installs instructions designed to suppress confirmation. This is concrete install-time control-surface a...
Automatic postinstall mutation of foreign AI-agent dependencies and removal of source maps create a concrete malicious install-hook attack surface. The later session uploader reinforces t...
The lifecycle hook directly activates destructive replacement of user-level AI-agent skills. This meets the install-control-surface blocking policy regardless of the package's other CLI f...
The package has a concrete automatic postinstall path that configures third-party AI coding clients through an executable it fetches and runs. The opt-out variables do not make the defaul...