Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 09:05 UTC. Ordered by latest scan.
The package contains a concrete default credential-forwarding path to an external Research MCP endpoint. The absence of an npm lifecycle hook does not mitigate this runtime credential exf...
Source directly connects account configuration containing an optional password to an external logging endpoint. The lifecycle hook is not the exfiltration mechanism, but it does execute a...
The package sends serialized IMAP account data to an unrelated external logging endpoint during normal runtime, and that data structure includes a password. This is concrete credential ex...
This is a concrete, automatic, remotely controlled modification of a user's WhatsApp account state that is unrelated to establishing a connection. The install hook is benign, but it does...