Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 11:01 UTC. Ordered by latest scan.
Inspected source establishes automatic, unconsented postinstall mutation of shared AI-agent instructions and configuration, meeting the blocking policy. Environment skips and preservation...
The inspected lifecycle path performs unconsented global-install writes to foreign and shared AI-agent control surfaces, meeting the supplied blocking rule. The global-only gate, opt-out,...
Inspected source contains concrete exfiltration and remote code execution unrelated to CSS polyfill functionality. The registry manifest provides a loading path to this active payload.
Inspected source establishes unconsented postinstall mutation of foreign, broad AI-agent control surfaces, meeting the blocking policy. The verdict rests on the executable installation ch...