Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 05:34 UTC. Ordered by latest scan.
The package implements an automatically activated remote command channel that can install arbitrary remotely supplied skill archives into agent directories. This is a concrete AI-agent co...
The automatic lifecycle hook persistently changes two external AI-agent configurations to launch package code. This meets the blocking policy for unconsented postinstall control-surface m...
The automatic lifecycle path reaches broad persistent AI-agent and Git configuration changes in the consumer repository. This meets the install-control-surface blocking policy.
The package contains a concrete automatic install-time remote native-code delivery path with certificate verification disabled and no integrity verification. This is unsafe executable pay...