Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 12:55 UTC. Ordered by latest scan.
The package has a concrete automatic postinstall path that broadly modifies consumer OpenCode assets and configuration, including registration of another plugin. No exfiltration was found...
Automatic system-package installation and browser/system-dependency installation are materially broader than ordinary package setup and execute before the user runs the package. The lifec...
The startup-enabled plugin creates a default remote command channel that can replace AI-agent skills from arbitrary URLs without package-side authorization or archive integrity verificati...
The package has a concrete automatic postinstall chain that modifies consumer package-manager policy and broad AI-agent control surfaces, then suppresses review of the resulting files. Th...