Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 06:14 UTC. Ordered by latest scan.
The package creates a concrete automatic chain from npm postinstall to an externally fetched executable that installs agent/editor hooks. This meets the install-control-surface blocking p...
The source establishes a concrete default exfiltration path for rich runtime records to package-embedded external webhooks. Lack of an install hook does not remove this runtime data-discl...
The source establishes an automatic postinstall chain that mutates consumer AI-agent settings and installs plugins, reinforced by a detached persistence mechanism. This meets the blocking...
This is concrete remote code execution on import from a hard-coded package-controlled endpoint. Signature verification authenticates the operator's payload but does not make arbitrary rem...