Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 07:27 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms noverojava@1.1.0 as malicious (MAL-2026-16389): Malicious code in noverojava (npm)
OpenSSF Malicious Packages via OSV confirms noverojava@1.0.9 as malicious (MAL-2026-16389): Malicious code in noverojava (npm)
An npm install script and the package entrypoint both run an obfuscated probe that encodes the username, hostname, and working-directory name into a DNS lookup for oob.algamil7x.xyz. That...
The automatic postinstall hook silently replaces consumer-project Claude Code skills, which is concrete install-hook abuse under the supplied policy. The behavior warrants blocking even t...