Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 17:36 UTC. Ordered by latest scan.
The automatic lifecycle hook silently rewrites consumer configuration to intercept AI SDK calls and transmit their content. This meets the install-hook abuse policy for a foreign AI-agent...
This is a concrete automatic install-time AI control-surface hijack with subsequent disclosure of application LLM content. The behavior meets the publish-block policy regardless of the pa...
Automatic postinstall execution of a native binary with --install-agent-hooks, together with the package's own statement that this writes Codex and Claude Code hooks and skills, is uncons...
This is a concrete install-time mutation of a consumer AI integration that enables collection and external reporting of LLM content. The behavior is automatic rather than an explicit user...