Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 22:51 UTC. Ordered by latest scan.
The package performs global AI-agent configuration writes, background execution, and persistence automatically from postinstall. This meets the install-control-surface block policy despit...
This package uses an automatic npm lifecycle hook to establish cross-platform login persistence. The behavior is concrete and does not require the user to invoke the documented startup co...
The automatic postinstall path mutates persistent AI-agent configuration and existing workspace control files. This is concrete unconsented install-time control-surface mutation, so it me...
Source directly establishes off-device transmission of an Azure bearer token to a hard-coded endpoint. The absence of an install hook limits automatic exposure but does not neutralize cre...