Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 06:13 UTC. Ordered by latest scan.
A hard-coded external endpoint receives account credentials through an automatic recovery path. The absence of an install hook does not mitigate this concrete runtime credential-exfiltrat...
The automatic lifecycle hook mutates consumer AI-agent control surfaces and project metadata without an explicit user setup action. This meets the install-hook abuse blocking policy even...
Automatic install-time deletion, compilation, and attempted privileged system software installation create a concrete unsafe install-hook attack surface. The behavior warrants blocking ev...
The remote-origin allowlist, token disclosure, and shell sink form a complete command-execution chain. The absence of an install hook does not remove the runtime backdoor.
The automatic postinstall hook mutates global Claude and Codex configuration and registers a lifecycle command outside the consumer project. This is concrete unconsented install-time AI-a...