Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 11:27 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms kartykgithub-takedown-a@1.0.1 as malicious (MAL-2026-16248): Malicious code in kartykgithub-takedown-a (npm)
OpenSSF Malicious Packages via OSV confirms kartykgithub-takedown-b@1.0.0 as malicious (MAL-2026-16249): Malicious code in kartykgithub-takedown-b (npm)
Postinstall writes a first-party skill into many foreign AI-agent skill directories under the user home, which is unconsented mutation of a broad agent control surface. README claims of a...
postinstall copies or downloads a native binary and runs --install-agent-hooks, and the README states this writes Codex and Claude Code hooks, skills, and a Codex setting. That is unconse...