Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 19:01 UTC. Ordered by latest scan.
postinstall writes a bundled agent skill into ~/.codex/skills and ~/.claude/skills, which is unconsented mutation of foreign AI-agent control surfaces. That matches a blocking install-tim...
The postinstall hook writes FocalAPI skills into many third-party agent skill directories under the user home without a separate user command. That is unconsented install-time mutation of...
The published main module is only an import-time fetch of /Profile followed by a POST of that body to /addPost, with no helper API. Combined with an empty manifest and no install hooks, t...
This package creates a concrete automatic supply-chain payload path by accepting and deploying an opaque remote native binary without certificate or integrity verification. The lifecycle...