Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 22:51 UTC. Ordered by latest scan.
The automatic lifecycle path combines foreign agent configuration writes with deliberate bypass of an existing agent safety hook. That bypass satisfies the blocking exception despite the...
The inspected chain establishes automatic postinstall mutation of foreign AI-assistant control surfaces, meeting the blocking policy. Package-related skill content and skip guards do not...
The inspected postinstall chain performs unconsented mutation of a foreign AI-agent control surface, meeting the supplied blocking policy. Compatibility intent and conditional file existe...
The inspected source establishes an automatic external installation beacon unrelated to utility functionality. This constitutes install hook abuse, although the source does not demonstrat...