Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 12:34 UTC. Ordered by latest scan.
This is an unconsented postinstall chain that executes a mutable remote payload and mutates an AI-agent control surface. The combination is concrete install-hook abuse rather than ordinar...
The automatic lifecycle hook performs broad global AI-agent configuration changes rather than limiting setup to an explicit command or package-owned location. This meets the install-contr...
The package contains a reachable automatic remote-code execution path: curl output from a package-controlled endpoint is piped to sh. The lack of an npm install hook does not mitigate exe...
This is an unconsented postinstall mutation of a foreign AI-agent executable surface. The package transparently performs the replacement, but it supplies opaque native payloads that take...