Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 16:53 UTC. Ordered by latest scan.
Password login is silently sent to a hardcoded unofficial gateway rather than Facebook, which is concrete credential theft. Missing install hooks and optional npm update install do not re...
The postinstall hook writes Claude Code skills into the consumer project's .claude/skills directory without a user command, which is an unconsented install-time mutation of a foreign agen...
This package combines an automatic installation lifecycle hook with unconsented host package-manager and sudo attempts. It also harvests credentials from unrelated agent configuration for...
The package deliberately and silently exports account metadata and broad application logs to an external host during ordinary use. The install hook is not the attack, but the runtime tele...