Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 08:48 UTC. Ordered by latest scan.
The published entrypoints contain active, targeted browser disruption that is unrelated to the package’s apparent UI component purpose. This is concrete protestware behavior and warrants...
The browser bundle implements targeted, disruptive behavior unrelated to user registration. The conditional trigger does not make the page disruption or unsolicited audio benign.
The inspected browser bundle contains targeted disruptive behavior: it disables page interaction and loops externally hosted audio under language, host, and timing conditions. This suppor...
Inspected source confirms targeted browser disruption and unsolicited looping audio in dist/465.js. This is active protestware behavior, so the package should be blocked.