Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 06:49 UTC. Ordered by latest scan.
The package establishes automatic hooks during postinstall in a foreign AI-agent settings file and retains a background npx execution path. These are concrete install-hook and persistence...
Automatic installation mutates a broad AI-agent instruction location outside the project. This meets the install-control-surface blocking policy regardless of the otherwise ordinary updat...
This is a concrete unconsented install-time mutation of a consumer project's AI-agent configuration and MCP approval state. The optional dashboard request is separately gated, but it does...
The automatic lifecycle script mutates a foreign project's Claude configuration and approval policy, including broad MCP enablement and automatic Playwright MCP approval. This is concrete...