Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 22:07 UTC. Ordered by latest scan.
The source establishes automatic, unconsented postinstall mutation of a foreign AI-agent control surface, which meets the blocking policy. The limited skill scope and absence of exfiltrat...
The inspected lifecycle chain performs unconsented changes to foreign AI-agent control surfaces and explicitly disables a safety preload. These concrete behaviors exceed guarded package-o...
Source establishes automatic, unconsented install-time mutation of foreign AI-agent control surfaces, accompanied by targeted safety-preload removal. This meets the blocking policy despit...
Source establishes automatic postinstall mutation of foreign AI-agent control surfaces, which meets the blocking policy. Package-related skill content and installation guards do not neutr...