Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 22:50 UTC. Ordered by latest scan.
The package performs an unconsented external runtime installation during postinstall, creating a supply-chain execution path outside npm's declared dependency set. The pinned version and...
This package performs unconsented install-time system mutation and automatically accesses foreign credential stores during normal startup. The behavior is concrete and high impact even th...
The package contains a concrete credential-collection and external-upload path with a hard-coded remote default. The lack of an install hook and the confirmation prompt reduce stealth but...
This is an automatic remote-native-code execution chain with no independent payload authentication. The installer also weakens macOS execution protections for that remote payload.
This is a concrete automatic postinstall mutation of a foreign AI-agent control surface. Guarded anchors reduce accidental breakage but do not provide user consent for the host rewrite.