Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 10:21 UTC. Ordered by latest scan.
The manifest's postinstall hook reaches code that automatically writes to multiple AI-agent configuration locations without a consent prompt. This meets the block criterion for unconsente...
The package automatically mutates global AI-agent instruction directories during postinstall, creating an unconsented agent control surface. This matches the install-hook blocking policy...
The postinstall hook reaches code that mutates broad AI-agent configuration locations without a consent prompt. This meets the blocking policy for unconsented installation-time control-su...
The `project worktime` command directly pipes a downloaded script into bash, and the command is exported for CLI use. This concrete remote code execution behavior supports blocking the pa...