Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 10:34 UTC. Ordered by latest scan.
This is an unconsented install-time mutation of a foreign AI-agent control surface, with persistent automatic execution of another registry package. The absence of observed secret theft d...
This package performs an automatic postinstall mutation of global AI-agent configuration, including a managed instruction block in an existing Codex control file. That is concrete install...
The install hook itself is limited, but the executable contains an automatic hard-coded network beacon that discloses host metadata on normal use. The self-dependency adds supply-chain risk.
The automatic global lifecycle path mutates broad AI-agent configuration and enables a trusted plugin. The workspace guard does not mitigate the automatic global-install behavior.