Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 10:14 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms kartykgithub-takedown-a@1.0.0 as malicious (MAL-2026-16248): Malicious code in kartykgithub-takedown-a (npm)
The published runtime combines automatic source-code uploads with broad credential forwarding to a remote endpoint. Although activation is user-invoked and not install-time, this is concr...
This is unconsented postinstall mutation of a broad AI-agent control surface, executed through opaque bundled native code. The opt-out does not establish prior consent for the default ins...
The published postinstall hook writes Claude Code skills into the consuming project's .claude/skills folder, which is an unconsented foreign agent control-surface change. Product-looking...
Password login is silently sent to a hardcoded unofficial gateway rather than Facebook, which is concrete credential theft. Missing install hooks and optional npm update install do not re...