Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 23:29 UTC. Ordered by latest scan.
This is an automatic lifecycle-based remote native payload installer that disables TLS verification and has no visible integrity validation. The later launcher execution completes a concr...
The automatic postinstall and startup paths perform unconsented host-level package installation, including sudo attempts. This is concrete install-hook abuse; credential discovery adds ma...
This is concrete unconsented postinstall mutation of a consumer project’s broad AI-agent control surfaces, coupled with review evasion and instructions to expose credentials. No automatic...
The source establishes automatic postinstall mutation of multiple unrelated AI-agent configuration surfaces, including default activation of a Codex plugin and MCP server. This is concret...