Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 21:18 UTC. Ordered by latest scan.
Inspected source establishes unconsented postinstall mutation of broad, foreign AI-agent control surfaces, meeting the blocking policy. This conclusion rests on executable lifecycle behav...
Source proves unconsented postinstall mutation of a foreign, global AI-agent control surface, meeting the explicit blocking policy. The verdict rests on the automatic configuration write,...
The inspected source establishes automatic data exfiltration during installation. The security research label does not neutralize the active collection and transmission behavior.
The inspected source establishes unconsented postinstall mutation of a foreign, user-level AI-agent control surface, which meets the supplied blocking policy. The interactive prompt and m...