Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 06:50 UTC. Ordered by latest scan.
The package has a concrete automatic postinstall chain that broadly mutates foreign AI-agent skill directories. Its apparent product purpose does not establish consent for this install-ti...
The source establishes a complete runtime chain from application input to package-selected external webhooks. The absence of an install hook does not mitigate this active data-exfiltratio...
The automatic lifecycle hook modifies existing agent configurations and installs a package-controlled MCP command without an explicit user setup action. This meets the install-hook abuse...
This is an unconsented install-time mutation of a foreign AI-agent control surface with a wildcard command hook. It meets the install-hook abuse blocking policy even without proving exter...