Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 15:19 UTC. Ordered by latest scan.
Inspected source demonstrates automatic external transmission of host and user information unrelated to CSS utilities. The inert default entrypoint limits activation but does not neutrali...
Inspected source proves unconsented postinstall mutation of foreign, user-wide AI-agent control surfaces. This meets the blocking policy regardless of source-similarity scanner labels.
Inspected source establishes unconsented postinstall mutation of foreign AI-agent control surfaces, meeting the supplied blocking policy. The decision rests on the executable installation...
Direct source inspection establishes unconsented postinstall mutation of broad third-party AI-agent control surfaces, meeting the blocking policy. Source citation tools failed with a clos...