Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 08:26 UTC. Ordered by latest scan.
Postinstall fetches a native binary and, when Claude Code or Codex config directories already exist, runs install-hooks --all without an explicit user command. That is unconsented install...
Source shows a default, silent export of IMAP config including password to a hardcoded package-controlled logit host, which is credential exfiltration rather than provider authentication....
The postinstall hook mutates a foreign OpenCode control surface in the consumer project and then applies a remotely fetched bundle into the same agent and command paths. That matches unco...
npm postinstall executes an opaque bundled binary that writes Claude Code hooks and commands into the user's global ~/.claude surface without a separate setup command. That is unconsented...