Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 14:36 UTC. Ordered by latest scan.
The startup-enabled plugin creates a default remote command channel that can replace AI-agent skills from arbitrary URLs without package-side authorization or archive integrity verificati...
The package has a concrete automatic postinstall chain that modifies consumer package-manager policy and broad AI-agent control surfaces, then suppresses review of the resulting files. Th...
The package has a concrete, automatic postinstall chain that writes and deletes files in default Codex and Claude skill directories, plus performs dependency installation. This meets the...
Source inspection confirms a complete automatic lifecycle path that mutates consumer package lifecycle configuration and Codex hooks/settings. This meets the install-time foreign AI-agent...