Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 09:33 UTC. Ordered by latest scan.
The published browser entrypoint contains targeted, delayed page disruption and external audio playback. This is concrete protestware behavior, so the package should be blocked.
The package entrypoint contains a delayed, geographically and linguistically targeted browser disruption that plays looping political audio. This is concrete protestware behavior, so the...
The npm postinstall hook unconditionally writes a package-owned MCP server entry to Claude and Codex user configuration. This meets the policy for blocking unconsented install-time mutati...
Source inspection confirms an automatic npm postinstall writes package-controlled scripts into an existing consumer Claude Code control surface, including hooks and session startup. Under...