Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 16:54 UTC. Ordered by latest scan.
This package uses an automatic npm lifecycle hook to install and prune global skills for two separate AI-agent products. That concrete cross-agent control-surface mutation meets the insta...
This is an unconsented postinstall mutation path for external AI-agent control surfaces, implemented through an opaque native executable. The unchecked remote-binary fallback increases in...
The automatic postinstall hook persistently mutates both Codex and Claude skill locations and installs additional user-level dependencies. This meets the install-control-surface policy fo...
This is an unconsented postinstall mutation of a foreign AI-agent control surface combined with automatic remote payload delivery. The signature checks and conflict handling do not neutra...