Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 15:26 UTC. Ordered by latest scan.
postinstall mutates a foreign Claude Code skill directory in the consuming project without a user command, which is unconsented agent-control-surface hijack. Skill text looks product-rela...
Postinstall automatically runs a compiled binary that writes this third-party package's hooks and prompts into Claude Code's user directories, a foreign machine-wide agent control surface...
The install hook downloads and installs an unverified native binary from a raw IP while disabling TLS checks, which is a concrete remote payload dropper. The launcher then executes that b...
Source shows an unconsented npm postinstall write into Claude Code's project hooks.json with a wildcard PreToolUse command. That is a foreign, broad agent control-surface mutation and mee...