Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 17:32 UTC. Ordered by latest scan.
The inspected lifecycle chain performs an unconsented install-time mutation of a foreign AI-agent control surface, meeting the blocking policy. The local destination and overwrite guard l...
Source proves unconsented postinstall mutation of a broad AI-agent control surface, which meets the blocking policy. The block rests on the global configuration change, without assuming t...
The inspected global postinstall path performs unconsented mutation of foreign AI-agent configuration and broad instruction files, meeting the blocking policy. The local-install guard and...
The inspected source establishes unconsented postinstall mutation of two foreign, global AI-agent control surfaces. This meets the supplied blocking policy even though the registered MCP...