Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 15:10 UTC. Ordered by latest scan.
Default remote execution exports the configured Roark bearer token to a third-party host when the MCP execute tool is used. That is concrete credential exfiltration despite the absence of...
The package hides a remotely controlled kill switch in a photo-frame component and destroys the consumer page when its remote licence decision is negative. There is no install-time execut...
The absence of an install hook reduces automatic-install risk, but the source deliberately conceals the actual upstream provider and rewrites a Claude control surface to route user prompt...
The component contains a concrete, destructive action against the consuming application's DOM, guarded only by remote-controlled license status. No install hook is needed for this harmful...