Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 18:32 UTC. Ordered by latest scan.
Inspected source establishes unconsented postinstall mutation of a broad, foreign AI-agent control surface. This meets the explicit blocking policy regardless of the skills' package-relat...
The inspected lifecycle chain performs unconsented, forced writes across foreign AI-agent instruction surfaces. Package-specific skill names do not neutralize this broad automatic mutatio...
Source proves unconsented postinstall mutation of multiple foreign AI-agent control surfaces. Package-branded skill names do not remove the broad installation-time mutation covered by the...
The inspected lifecycle chain automatically invokes broad AI-client configuration without a consent step, meeting the install-time agent control-surface blocking policy. The native implem...