Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 13:21 UTC. Ordered by latest scan.
postinstall silently mutates the user's global Claude Code settings and turns on remote export of session prompts, replies, and tool traces. That is unconsented foreign agent-control-surf...
This package has no functional code but uses two unconsented automatic lifecycle hooks to exfiltrate host and CI information. The behavior is concrete install-time data collection and war...
This is concrete, unconsented install-time host data exfiltration with no corresponding package functionality. It is malicious install-hook abuse.
This package has no functional implementation but automatically exfiltrates host and CI-related metadata at install time. The behavior is concrete, unconsented, and unrelated to a legitim...