Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 11:36 UTC. Ordered by latest scan.
The package has no observed exfiltration or remote payload behavior, but its postinstall hook persistently modifies broad AI-agent skill locations. That concrete lifecycle control-surface...
This is concrete automatic install-time modification of multiple user-wide AI-agent control surfaces, not an explicit user-command setup. The injected instructions create a continuing pat...
This is an unconsented postinstall mutation of broad, foreign AI-agent control surfaces. The local payload and absence of secret theft do not neutralize the automatic cross-platform agent...
The automatic lifecycle hook broadly mutates consumer AI-agent configuration paths, meeting the install-control-surface blocking policy. No additional exfiltration or network behavior is...