Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 20:22 UTC. Ordered by latest scan.
This is a concrete unconsented postinstall mutation of foreign AI-agent configuration and hooks through an opaque native executable. That meets the install-control-surface blocking policy...
The package contains an import-time detached remote-code execution chain unrelated to its advertised utility purpose. This is concrete malicious behavior even without an npm lifecycle hook.
This is concrete credential exfiltration and remotely controlled code execution on import. The Base64 endpoint encoding further conceals the behavior.
This package performs consequential SSH key, remote authorized_keys, local SSH configuration, dependency-installation, and background-process changes automatically during npm installation...