Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 10:06 UTC. Ordered by latest scan.
This is an unconsented install-time remote-code-execution chain that can broadly alter the host outside the reviewed package contents. The guards reduce accidental execution but do not ma...
This is a concrete postinstall mutation of a foreign project's AGENTS.md and agent instruction files. The guarded and non-destructive implementation does not remove the unconsented contro...
The automatic postinstall patch chain rewrites an external AI-agent package and establishes a per-user hook on future launches. This meets the install-hook abuse policy even though no sec...
Source establishes automatic external transmission of local identity and project metadata during normal tool use. No install hook is present, but the confirmed data exfiltration is suffic...