Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 09:38 UTC. Ordered by latest scan.
The automatic postinstall hook mutates broad, user-level Claude Code and Codex instruction surfaces. This meets the install-hook policy for unconsented foreign AI-agent control-surface mu...
This is concrete destructive browser behavior hidden inside an ostensibly lightweight embedding component. It is reachable during normal component use and lacks transparent documentation...
The default runtime path exports credentials and arbitrary submitted code to a remote endpoint. The lack of install hooks does not mitigate this active credential-exfiltration behavior.
Although installation itself only displays a message, explicit package commands fetch and execute opaque remote shell content in the consumer project and install server-provided AI contro...