Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 15:46 UTC. Ordered by latest scan.
This release automatically modifies foreign AI-agent configuration during npm installation and adds Windows login persistence. Those actions meet the install-hook abuse blocking policy ev...
This package performs unconsented, automatic system package installation from a registry lifecycle hook and retries it during normal startup. Its external agent-hook refresh behavior adds...
The package contains concrete AI-agent instruction injection and undisclosed host/error telemetry in its executable entrypoint. The absence of an install hook limits installation impact b...
The package contains a concrete, default-on exfiltration path for sensitive email and cloud-account metadata to a non-service endpoint. Its benign local postinstall symlink setup does not...