Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 20:24 UTC. Ordered by latest scan.
This package contains a complete automatic install-time chain for secret exfiltration and remote shell access. The behavior is malicious and requires blocking.
This is an automatic install-time credential-harvesting and reverse-shell payload, reinforced by explicit typosquat metadata. It warrants blocking.
This is an automatic install-time credential-exfiltration and reverse-shell chain, not a user-invoked administrative feature. The hard-coded external server and typosquat metadata further...
The package's automatic postinstall makes broad changes to consumer and user AI-agent configuration, then persists a future lifecycle command in the consumer project. This meets the block...