Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 16:16 UTC. Ordered by latest scan.
The automatic postinstall hook modifies global Cursor agent configuration and skills, rather than requiring an explicit user setup action. This meets the install-hook abuse boundary for a...
The package has a concrete automatic install-time chain that modifies both Codex and Claude user skill stores and deletes stale destination content. This meets the install-control-surface...
The source establishes automatic remote export of sensitive email-account metadata and broad diagnostic output during ordinary client use. The bounded workspace-link postinstall hook does...
The package has a concrete automatic postinstall chain that mutates consumer and user-home AI-agent configuration and enables package plugins. This meets the policy threshold for unconsen...