Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 16:54 UTC. Ordered by latest scan.
This package has a concrete automatic postinstall path that persistently modifies user-level AI-agent configuration and hooks. The global-install guard does not provide explicit user cons...
The package contains a reachable boot path that automatically establishes persisted SSH-key access and listens on all interfaces. Although this is not an npm install hook, it is a concret...
This is a concrete automatic postinstall mutation of broad, foreign Codex and Claude agent configuration surfaces. The documented notice does not convert lifecycle execution into explicit...
The automatic lifecycle hook modifies user-wide agent configuration locations for both Codex and Claude. This meets the install-hook abuse policy even though no source-level exfiltration...