Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 21:01 UTC. Ordered by latest scan.
The active import-time entry point harvests credentials and sensitive runtime data and exfiltrates it to an unrelated external host. This is concrete credential and data exfiltration beha...
Active import-time collection and export of cloud credentials, environment variables, and Kubernetes secrets is concrete malicious behavior. The absence of an install hook does not reduce...
The active entrypoint implements unconsented credential and secret collection followed by transmission to an unrelated hard-coded endpoint. This is concrete data exfiltration behavior.
The active entrypoint implements automatic secret collection and export to an unrelated external host. This is concrete credential and data exfiltration.