Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 01:27 UTC. Ordered by latest scan.
The automatic, heavily obfuscated preinstall loader has concealed payload-handling and child-process capability, which is concrete install-hook abuse. The normal SDK entrypoint does not j...
The package contains an automatic, deliberately obfuscated install hook that reconstructs and launches a hidden payload. This is concrete install-hook abuse and is not justified by the ex...
The automatic postinstall invocation of install-hooks --all against existing Claude and Codex directories is a concrete unconsented mutation of a foreign AI-agent control surface. The opt...
The automatic postinstall hook writes to both agent platforms' user skill directories without an explicit user setup action. This meets the policy threshold for unconsented install-time m...