Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 23:51 UTC. Ordered by latest scan.
The undocumented, import-time hidden launch and directory watch establish a concrete covert execution chain. The lack of a network sink does not remove the local execution and staging risk.
The package contains concrete covert payload extraction and user-directory executable placement activated on import. The delayed watcher and carrier deletion reinforce malicious intent de...
The automatic global-install path changes broad AI-agent configuration and adds login persistence. Its self-updating launcher compounds the unconsented lifecycle chain.
The postinstall hook performs unconsented, broad mutation of a foreign AI-agent control surface. This meets the blocking policy for lifecycle control-surface abuse.