Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 14:33 UTC. Ordered by latest scan.
The manifest-reachable CommonJS entrypoint loads dist/index.js, which sends supplied credentials to an unrelated hardcoded gateway. The absence of an install hook does not remove this run...
The source establishes an automatic, unpinned self-install chain into a remote sandbox and a lifecycle hook that persistently changes command execution and shell configuration. This match...
This is an unconsented postinstall mutation of a broad AI-agent control surface that enables external collection of sensitive Claude session content. The automatic global configuration ma...
postinstall copies this skill into Claude, Gemini, Codex, and Antigravity skill directories and, for Claude Code, injects a machine-wide SessionStart hook into user-level settings.json wi...