Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 13:33 UTC. Ordered by latest scan.
The automatic lifecycle path launches a persistent process that can modify foreign AI-agent workspace configuration, rather than limiting setup to the installed package. This is an uncons...
The automatic lifecycle hook writes and prunes skills in both Codex and Claude user directories, meeting the install-time AI-agent control-surface abuse policy. The additional user-level...
This is a concrete, unconsented install-hook abuse chain that broadly mutates and persistently controls consumer project files. No self-dependency or install-time exfiltration was found,...
The inspected code establishes automatic, noninteractive consumer-project and AI-agent plugin mutation during postinstall, with detached persistence of reconciliation. This exceeds transp...