Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 05:10 UTC. Ordered by latest scan.
The published main module immediately runs an obfuscated payload that loads shell execution, filesystem access, and an HTTP client. That is hidden import-time attack behavior, not a logge...
The published plugin entries hide a fetch of option-derived content and execute it with Node require during ordinary cryptoPlugin setup. That is remote code execution, separate from the l...
Automatic install hooks harvest credentials and phone home to an unrelated oast.site host, which is concrete install-time malware. The empty library entry and local-only comments do not r...
The package embeds a concealed, configuration-derived remote code execution path in its runtime entrypoints. This is concrete attack behavior beyond the declared encryption feature.