Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 14:54 UTC. Ordered by latest scan.
Inspected source establishes automatic collection and external transmission of local metadata during installation and import. This concrete data exfiltration supports blocking despite the...
Inspected source establishes automatic collection and external transmission of local host and project metadata during installation and import. This concrete exfiltration behavior supports...
Inspected source establishes automatic collection and external transmission of local metadata during installation and import. This concrete data exfiltration supports blocking independent...
Source confirms automatic host and project metadata exfiltration during installation and import. This concrete behavior supports blocking independently of the scanner fingerprint.