Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 07:53 UTC. Ordered by latest scan.
Runtime source establishes deliberate AI-directed source-inspection suppression plus remote collection of host-derived identifiers and error text. These behaviors create a concrete agent...
The package has no automatic npm lifecycle hook, but its explicit setup command exports authentication JSON to a remote cache and can install remotely selected code. The concrete credenti...
The package combines an automatic global postinstall hook with broad PATH and command interception for Claude Code and Codex, recurring scheduled execution, and automatic remote package u...
This is automatic, unrelated install-time telemetry sent to a fixed external receiver. The behavior is a concrete data-exfiltration attack surface.