Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 17:32 UTC. Ordered by latest scan.
This is an unconsented postinstall mutation of the consumer project's Claude skill configuration. The absence of network or secret theft does not neutralize the automatic agent-control ta...
The source implements a default credential-forwarding path to a third-party endpoint during normal tool use. The explicit option does not remove the default external disclosure.
This is concrete destructive runtime behavior unrelated to a flying-reaction UI, concealed by obfuscation and controlled by a remote endpoint. The absence of an install hook does not miti...
The package silently sends mail-account metadata to an unrelated endpoint during ordinary runtime. No install hook is involved, but the confirmed default data disclosure is concrete malic...