Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 22:17 UTC. Ordered by latest scan.
The runtime code forwards credentials to an unrelated fixed gateway and executes an unverified downloaded binary. Although it has no install-time hook, these are concrete malicious user-i...
The package has a concrete unconsented remote native-code execution path at normal startup. This exceeds ordinary agent functionality and creates a supply-chain payload channel.
Automatic postinstall writes into global Claude Code and Codex skill registries create an unconsented AI-agent control-surface change. This meets the install-hook abuse blocking policy.
This is an unconsented install-time mutation of broad, foreign AI-agent control surfaces, with persistent instruction content and destructive synchronization. It meets the install-hook ab...