Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 23:50 UTC. Ordered by latest scan.
The package performs an automatic postinstall write to a consumer project's .claude skill directory. This concrete AI-agent control-surface mutation meets the publish-block policy.
The automatic global lifecycle path installs persistent Claude Code hooks and agent configuration. This meets the policy threshold for blocking unconsented install-time mutation of a broa...
The package automatically exports potentially credential-bearing account settings to a package-controlled, unrelated endpoint. This is concrete credential exfiltration rather than ordinar...
The automatic global-install chain reaches a user-level Claude agent configuration with no interactive consent. This meets the install-control-surface blocking condition.
The automatic lifecycle hook makes unconsented changes to Claude Code's skill and command directories. This meets the install-control-surface blocking policy.
Opaque bundled code is decrypted using remotely supplied material and actively executed through the Function constructor. This is a concrete remote code execution path, not an inert encry...
The source implements active, silent transmission of account configuration to an unrelated endpoint, including data that can contain IMAP credentials. This is concrete credential exfiltra...
The automatic lifecycle hook combines deliberate obfuscation, staged payload handling, filesystem writes, and process execution. This meets the install-hook abuse boundary for blocking pu...
The automatic lifecycle chain performs broad AI-agent configuration mutation and installs an additional executable MCP dependency. This meets the install-control-surface blocking rule.
The package automatically rewrites a consumer application's AI module resolution during postinstall, then transmits intercepted AI run contents. This is a concrete unconsented AI-agent co...
Hidden extraction and detached execution of an opaque PowerShell payload is concrete malware behavior, not environment configuration functionality. Automatic activation from both runtime...
The package contains a concrete automatic install-time collection and outbound transmission of local system identifiers. This is malicious data exfiltration rather than ordinary package s...
The automatic lifecycle hook performs broad OpenClaw skill installation without user invocation. This meets the install-time AI-agent control-surface mutation block policy.
The package performs an automatic postinstall overwrite of the user's OpenClaw skills directory. This meets the install-time AI-agent control-surface mutation block policy.
The automatic lifecycle path modifies global Claude Code configuration and registers future agent hooks without consent. This meets the install-control-surface blocking boundary.
The automatic postinstall hook mutates two foreign, global AI-agent control surfaces and installs executable MCP entries without user consent. This meets the install-control-surface block...
The automatic post-install hook persistently modifies broad AI-agent configuration files and injects package-preference instructions. This meets the blocking policy for unconsented lifecy...
The package contains and automatically activates a hidden encoded-PowerShell launcher from both its library and CLI entrypoints. This is concrete malicious execution behavior unrelated to...
The hidden import-time request interception, recurring daemon, and remote update mechanism are unrelated to a general CLI and are concealed by obfuscation. This is concrete malicious pers...
The automatic lifecycle hook modifies the consumer's .opencode configuration and agent content. That is concrete install-hook abuse under the stated policy.
The postinstall hook performs unconsented mutation of a consumer AI-agent control surface and applies remote package-controlled content. Signature checks limit third-party tampering but d...
The automatic npm lifecycle performs broad AI-agent configuration mutation without an explicit user command or target selection. This meets the install-control-surface blocking rule even...
The source establishes a default-enabled reporting loop that exports identifiable installation, host, path, and user-activity metadata to a hard-coded third-party endpoint. No install hoo...
The automatic global lifecycle chain modifies Claude agent configuration and can remove existing matching paths. This meets the blocking policy for unconsented postinstall mutation of a f...
The automatic lifecycle chain mutates and deletes user AI-agent configuration outside the installed package. This is a concrete unconsented install-hook control-surface attack.