Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 12:35 UTC. Ordered by latest scan.
This is a concrete remote code execution path coupled to global AI-agent hook installation and instructions designed to suppress inspection. The absence of an npm lifecycle hook does not...
OpenSSF Malicious Packages via OSV confirms html-to-gutenberg@4.2.21 as malicious (MAL-2026-6359): Malicious code in html-to-gutenberg (npm)
The automatic lifecycle hook, self-dependency constrained to an older release, project environment access, and database authorization seeding form a concrete install-hook abuse chain. The...
Automatic postinstall rewrites the consumer's Claude Code user settings and enables remote logging of prompts, replies, and tool details. That is unconsented mutation of a foreign AI-agen...
The manifest-reachable CommonJS entrypoint loads dist/index.js, which sends supplied credentials to an unrelated hardcoded gateway. The absence of an install hook does not remove this run...