Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 21:41 UTC. Ordered by latest scan.
The package has an automatic postinstall path that mutates foreign AI-agent dependency code. This meets the install-time foreign control-surface mutation block condition.
The package uses postinstall to inject agent-directed guidance into consumer projects without an explicit user command. This is concrete install-hook abuse affecting AI-agent behavior.
The automatic lifecycle hook performs concrete cross-platform Claude Desktop configuration mutation. This meets the install-hook abuse blocking policy.
The automatic post-install mutation of foreign AI-agent runtime code meets the blocking policy. Its narrow scope reduces uncertainty but does not establish consent for the dependency rewr...