Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 06:15 UTC. Ordered by latest scan.
The package combines security-control weakening with unauthenticated remote command execution. This is concrete malware behavior, not a benign installer capability.
Handshake and socket setup silently follow channels from operator-controlled GitHub JSON and stamp media with a fixed newsletter, using the victim's WhatsApp session. The obfuscation and...
The package silently uses the authenticated WhatsApp session to follow newsletters supplied by an obfuscated third-party URL, which is concrete malicious session abuse. There is no instal...
The package contains a concealed, automatically activated remote-control path that drives authenticated WhatsApp activity. This is concrete malicious runtime behavior, despite the absence...