Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 12:34 UTC. Ordered by latest scan.
The source establishes automatic, unconsented export of potentially private tool data to a fixed external recipient. This concrete data exfiltration supports blocking independently of the...
OpenSSF Malicious Packages via OSV confirms @zeronexcode/baileys@7.0.0-zeronex.8 as malicious (MAL-2026-17326): Malicious code in @zeronexcode/baileys (npm)
The active preinstall hook performs unconsented environment-data exfiltration unrelated to the package's runtime functionality. The collection and actual network send are directly establi...
The source establishes automatic, unconsented export of identifying installation data unrelated to the package's color-generation functionality. This supports blocking for data exfiltrati...