Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 23:11 UTC. Ordered by latest scan.
This is concrete install-hook abuse: an automatic npm lifecycle hook changes multiple unrelated AI-agent configurations and installs a session-controlling plugin. The conditional director...
The automatic hook modifies foreign AI-agent rule directories and deletes existing configuration, which meets the install-control-surface blocking policy. Its automatic remote native-bina...
The package has a concrete automatic install-time path that mutates multiple external AI-agent instruction surfaces. This meets the blocking policy for unconsented post-install control-su...
The package performs unconsented post-install mutation of multiple consumer AI-agent control surfaces. This meets the blocking policy for lifecycle-based control-surface modification.