Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 18:12 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms plogme@1.0.0 as malicious (MAL-2026-16199): Malicious code in plogme (npm)
The automatic postinstall hook mutates a foreign consumer project's Claude Code skills and deletes existing skills. This meets the install-time AI-agent control-surface abuse policy despi...
The automatic postinstall hook modifies broad foreign AI-agent configuration surfaces and the user environment. This meets the install-hook abuse policy even without confirmed secret theft.
The package has a concrete automatic postinstall path that modifies host software through package managers, including sudo, and repeats it at runtime. This is unsafe install-hook abuse ra...
This is an automatic, unverified remote payload execution chain during npm installation. Platform filtering does not constrain the code supplied by the latest release or redirect target.