Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 19:08 UTC. Ordered by latest scan.
The automatic lifecycle script both installs an unverified remote executable and writes behavior-bearing configuration into multiple foreign AI-agent directories. This is concrete install...
The hard-coded default external API host and automatic forwarding of a consumer access token form a concrete runtime credential-exfiltration path. The absence of lifecycle hooks limits th...
The default external endpoint, cookie-token forwarding, and administrative POST operations form a concrete exfiltration path unrelated to the declared package presentation. There is no in...
The automatic postinstall mutation of a global Claude Code command surface is concrete, broad, and unconsented. This meets the install-control-surface block policy even though the install...