Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 04:27 UTC. Ordered by latest scan.
The automatic lifecycle hook mutates third-party agent-plugin code and redirects its configuration under the package's namespace. Source-map removal further conceals the resulting install...
The package executes a persistent OpenCode configuration change automatically at install time, rather than through an explicit user command. This is concrete AI-agent control-surface hija...
The lifecycle hook performs automatic, non-interactive modification of a foreign AI-agent configuration directory. This meets the install-control-surface blocking criterion even though no...
The automatic lifecycle chain changes consumer package-manager settings and broad AI-agent control surfaces, then installs a Git hook. This meets the policy threshold for an unconsented i...