Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 17:05 UTC. Ordered by latest scan.
Inspected source proves automatic system reconnaissance and external data transmission unrelated to a CSS polyfill. This is an active data-exfiltration attack when the registry module is...
The inspected source establishes unconsented postinstall mutation of global Claude Code command settings, which meets the blocking policy. Package-aligned statusline functionality does no...
Inspected source proves unconsented postinstall mutation of two foreign global AI-agent control surfaces. This meets the explicit blocking policy even without evidence of credential theft.
Inspected source proves unconditional postinstall mutation of foreign global AI-agent configurations. This meets the explicit blocking rule independently of scanner labels or citation cov...