Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 18:08 UTC. Ordered by latest scan.
The automatic postinstall performs remote shell execution and changes Codex plugin configuration during installation. Its global-install guard limits exposure but does not establish conse...
The automatic postinstall broadens a package installation into persistent global AI-agent configuration mutation. The installed content includes instructions for privileged account actions.
This is unconsented install-time mutation of a consumer project and its AI-agent control surface, followed by persistence through the consumer postinstall hook. The detached reconciliatio...
This is an unconsented postinstall mutation of broad AI-agent control surfaces combined with instructions that facilitate credential disclosure and evade review. The lifecycle script also...