Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 09:03 UTC. Ordered by latest scan.
This is concrete, automatic credential and application-data exfiltration from the package entry point. The fixed external receiver and immediate execution establish malicious behavior.
The source contains a complete, import-triggered data-exfiltration path to an unrelated external webhook. This is concrete malicious behavior even though it has no install hook.
The package embeds package-controlled remote logging defaults and automatically transmits rich application records during ordinary ScanOrder use. This is concrete data exfiltration rather...
The package embeds active third-party webhook destinations and automatically sends rich runtime records to them during normal ScanOrder use. The absence of an install hook does not mitiga...