Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 13:10 UTC. Ordered by latest scan.
This is an automatic install-time remote native payload chain with disabled certificate verification. The payload is installed as an executable, creating a concrete supply-chain execution...
Automatic postinstall mutation of global Claude and Codex skill directories, coupled with an injected-task execution instruction, is a concrete AI-agent control-surface hijack. The absenc...
The automatic postinstall mutation of foreign AI-agent skill directories is concrete and unconsented. Normal Feishu OAuth handling does not remove that install-time control-surface risk.
The package establishes automatic hooks during postinstall in a foreign AI-agent settings file and retains a background npx execution path. These are concrete install-hook and persistence...