Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 14:42 UTC. Ordered by latest scan.
The postinstall hook drives a third-party Chrome MCP bridge to register a native messaging host without a user command, which is unconsented mutation of a foreign AI-agent control surface...
Postinstall downloads and installs an unsigned native binary from a hardcoded IP with TLS verification disabled, then the CLI executes it. That is a concrete remote payload chain, not a f...
Source shows a fake Cloudflare interstitial whose obfuscated script fetches, AES-decrypts, and follows a remote redirect_url. That is concrete malware behavior even though npm install its...
Automatic postinstall writes a native binary and config into ~/.grok, a foreign Grok agent control surface, from a different npm scope. That unconsented install-time hijack is concrete at...