Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 21:04 UTC. Ordered by latest scan.
This is an automatic postinstall mutation of a broad, foreign AI-agent control surface. The package installs event-triggered commands and permissions into global Claude Code configuration...
The package is a persistent telemetry agent that transmits local configuration content and cloud identity data after wiring itself into AI-agent hooks. The absence of an automatic npm lif...
The package has a concrete automatic postinstall hook that invokes an AI-agent skills synchronization command. This is unconsented install-hook abuse of a foreign control surface.
The package has a concrete automatic install-time credential-transmission path. Static icon exports do not mitigate that lifecycle behavior.