Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 23:32 UTC. Ordered by latest scan.
This package contains a complete, default-enabled runtime data-exfiltration path to hard-coded external webhooks. It is not install-time malware, but the undisclosed receiver and automati...
This is an unconsented install-time mutation of broad AI-agent control surfaces combined with deliberate review suppression and secret-handling instructions. The behavior meets the instal...
This is concrete credential exfiltration to a package-controlled third-party endpoint, activated by the package's core login flow. The automatic project-level updater increases supply-cha...
This package performs unconsented postinstall mutation of broad, foreign AI-agent control surfaces and the consumer project. That concrete lifecycle behavior meets the publish-block polic...