Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 19:41 UTC. Ordered by latest scan.
postinstall copies this skill into Claude, Gemini, Codex, and Antigravity skill directories and, for Claude Code, injects a machine-wide SessionStart hook into user-level settings.json wi...
The postinstall hook copies Claude Code skills into a consumer project's .claude/skills directory without an explicit setup command, which is unconsented mutation of a foreign AI-agent co...
The postinstall hook copies skills and agents into consumer .claude and .agents paths and writes Copilot instruction and hook files, which is unconsented mutation of foreign AI-agent cont...
The package performs the policy-defined malicious chain: automatic postinstall mutation of foreign AI-agent controls plus detached persistence. Its stated safety purpose does not establis...