Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 17:51 UTC. Ordered by latest scan.
Inspected source establishes unconsented postinstall mutation of broad AI-agent control surfaces, meeting the supplied blocking policy. The other inspected scanner hints do not establish...
Inspected source proves automatic host-data collection and transmission when the registry script loads. This concrete exfiltration behavior warrants blocking despite the empty default ent...
Inspected source establishes automatic reconnaissance and external transmission when the published registry script loads. This behavior is unrelated to a CSS environment-function shim and...
Inspected source establishes automatic host-data collection and external transmission unrelated to CSS polyfilling. The empty default entrypoint and absence of install hooks limit activat...