Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 21:06 UTC. Ordered by latest scan.
This is a concrete install-time remote-code-execution backdoor, not functionality required by the stated n8n health-monitor node. The listener is exposed on all interfaces and has no auth...
The source establishes a concrete credential and environment disclosure path to a remote endpoint in the default execution mode. The absence of lifecycle hooks limits activation to MCP us...
The package combines automatic host package installation with recurring lifecycle-enabled global self-updates and third-party agent-hook rewriting. These actions occur without an explicit...
Source directly establishes a fixed remote credential destination and persistent session handling. The explicit command trigger does not remove the credential-exfiltration risk of the unv...