Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 09:35 UTC. Ordered by latest scan.
This is an automatic lifecycle remote-payload chain with no integrity verification and disabled TLS validation. It creates a concrete route for arbitrary code execution through a remotely...
The automatic install hook broadly mutates a consumer project's AI-agent configuration and package-manager behavior, then installs reviewer-suppressing rules. This is concrete install-hoo...
The package uses postinstall to persist unrestricted Claude Code command hooks in a user-level configuration file. This meets the install-hook abuse blocking boundary.
The automatic postinstall hook performs broad global AI-agent skill installation and deletion rather than limiting setup to an explicit user action. This meets the install-control-surface...