Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 07:55 UTC. Ordered by latest scan.
Automatic postinstall writes a native binary and config into ~/.grok, a foreign Grok agent control surface, from a different npm scope. That unconsented install-time hijack is concrete at...
Source is a complete fake Cloudflare challenge that hides a remote fetch, AES-CTR decrypt, and URL redirect behind obfuscation. That is a working browser malware loader even though npm in...
Source is a fake Cloudflare challenge whose obfuscated script fetches, AES-CTR decrypts, and Function-executes a remote payload, then redirects the visitor. That is a concrete browser rem...
Source shows a random-named HTML dropper that impersonates Cloudflare, contacts a reconstructed API, decrypts the reply, and executes it with Function. That is a concrete browser remote-c...