Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 22:17 UTC. Ordered by latest scan.
This is an unconsented install hook that fetches executable payloads and performs broad host package-manager mutation. The absence of visible credential theft does not mitigate the concre...
The automatic lifecycle hook performs persistent, user-wide AI-agent configuration and shell-profile mutation. This meets the install-control-surface blocking policy even though the inspe...
The package contains a concrete runtime data-exfiltration path to an embedded external receiver, not merely a general-purpose request API. Its lack of an install hook limits the trigger b...
This is an automatic install-hook payload chain that downloads and executes unverified native code and mutates host software outside the npm package directory. Although no credential thef...