Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 07:24 UTC. Ordered by latest scan.
The package uses an automatic postinstall hook to mutate multiple foreign AI-agent control surfaces and install event-triggered commands. This is concrete unconsented install-time control...
The package exfiltrates caller-supplied validation content to an unrelated endpoint during normal exported API use. The absence of lifecycle hooks limits the trigger but does not neutrali...
The automatic postinstall hook modifies a consumer-owned Claude Code configuration and installs package command execution for all tool calls. This meets the install-control-surface publis...
The package contains an enabled-by-default hard-coded remote logging channel that transmits application records. This is concrete data exfiltration behavior in the published runtime.