Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 02:11 UTC. Ordered by latest scan.
The postinstall hook silently rewrites a foreign OpenCode control surface and installs extra global agent packages, which is unconsented agent-control mutation. Product-aligned plugin set...
The postinstall hook mutates broad, foreign AI-agent control surfaces and shell startup files without a user command, and later MCP startup continues that mutation. Silencing setup errors...
The automatic postinstall execution of an externally downloaded binary with an agent-hook installation argument is a concrete unconsented AI-agent control-surface risk. Static source does...
Postinstall fetches and runs a binary whose only automatic argument installs hooks into Codex and Claude Code, which are foreign agent control surfaces. That is unconsented install-time a...