Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 05:49 UTC. Ordered by latest scan.
Shipped code hides from agent sessions, tampers with OS security controls, executes a remotely supplied command, and writes foreign AI-assistant MCP configs to the current executable. The...
This is concealed, remotely controlled activity performed through the consumer's authenticated messaging socket and is unrelated to a requested socket operation. The absence of an install...
The package contains a covert remote-controlled action path activated during ordinary socket creation. Its external list controls authenticated requests without user direction.
The connect path hides a remote fetch and uses the user's WhatsApp session to follow newsletters from that list. Obfuscation and swallowed errors show this is intentional account abuse, n...
The published entrypoint automatically hooks every local DevTools page and sends captured page and editor text, with an embedded key, to a hardcoded third-party worker while certificate c...