Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 14:10 UTC. Ordered by latest scan.
This is malicious install-hook abuse: an automatic lifecycle hook mutates foreign OpenCode project configuration, lockfiles, and caches to control the installed plugin version. Runtime co...
The automatic postinstall hook mutates broad, foreign AI-agent configuration surfaces and the user's Python environment. This meets the install-control-surface blocking policy regardless...
The automatic postinstall remote-code execution is a concrete supply-chain attack surface, not a user-invoked feature. Its mutable unverified payload warrants blocking publication.
The automatic postinstall lifecycle mutates the consumer's Claude Code configuration and registers package code for every tool action. This meets the policy threshold for malicious AI-age...