Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 19:05 UTC. Ordered by latest scan.
Inspected executable code establishes automatic credential export to an external logging host through the active client startup path. The benign install hook does not neutralize this runt...
Inspected source proves unconsented postinstall mutation of foreign AI-agent control surfaces, including overwriting and pruning existing skills. This supports blocking under the agent co...
Inspected source establishes unconsented postinstall mutation of a foreign AI-agent control surface. This meets the blocking policy independently of scanner labels or citation coverage li...
Inspected source proves unconsented postinstall mutation of global Claude Code command hooks, meeting the blocking policy for AI-agent control surfaces. Same-vendor binary names and condi...