Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 18:22 UTC. Ordered by latest scan.
The postinstall hook downloads a native binary and non-interactively runs arkcli +connect --refresh to auto-detect local agents and install skills into them. That is unconsented install-t...
The automatic postinstall hook persistently changes the user's command environment and starts a restartable user service without an explicit setup command. This is unconsented install-tim...
The postinstall script writes into ~/.codex/skills and ~/.claude/skills, which is unconsented install-time mutation of foreign AI-agent control surfaces. That matches a publish block even...
The executable entry point harvests browser page data and transmits flag-like values or markup without an application-facing API or stated purpose. This is concrete data exfiltration beha...