Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 08:57 UTC. Ordered by latest scan.
The package contains a complete active data-export path from runtime logger records to package-selected webhook recipients. The absence of an install hook limits the trigger but does not...
The package is an obfuscated, remotely directed browser redirector presented as a security challenge. This is concrete deceptive traffic-routing behavior, not a package-aligned application.
This is an active, obfuscated browser redirect and visitor-data forwarding payload with no stated package functionality. It is not normal npm package behavior and conceals its remote dest...
The primary entrypoint performs an unconditional network beacon containing local host and user metadata to a third-party endpoint. This is concrete data exfiltration, even though the brok...