Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 11:09 UTC. Ordered by latest scan.
The automatic postinstall mutates a foreign consumer project's Copilot control surface and installs command hooks for later agent events. This is concrete install-hook abuse under the iso...
The automatic lifecycle hook mutates a broad, foreign AI-agent control surface and installs instructions designed to suppress confirmation. This is concrete install-time control-surface a...
Automatic postinstall mutation of foreign AI-agent dependencies and removal of source maps create a concrete malicious install-hook attack surface. The later session uploader reinforces t...
The lifecycle hook directly activates destructive replacement of user-level AI-agent skills. This meets the install-control-surface blocking policy regardless of the package's other CLI f...