Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 19:28 UTC. Ordered by latest scan.
The source establishes automatic, unconsented transmission of local identifying information to an unrelated endpoint during installation. This is concrete data exfiltration rather than an...
The automatic lifecycle performs concrete, unconsented data exfiltration unrelated to the package's date-formatting functionality. The collection and actual network send are directly esta...
Source proves automatic, unconsented export of identifying local information during installation. The external reporting behavior is unrelated to the package’s arithmetic functionality an...
The source proves automatic, unconsented export of local identifying information to an unrelated external recipient. This concrete install-time data exfiltration warrants blocking.