Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 21:07 UTC. Ordered by latest scan.
The automatic postinstall hook persistently mutates both Codex and Claude skill locations and installs additional user-level dependencies. This meets the install-control-surface policy fo...
This is an unconsented postinstall mutation of a foreign AI-agent control surface combined with automatic remote payload delivery. The signature checks and conflict handling do not neutra...
The package performs automatic install-time transmission of an environment credential to a remote endpoint. The absence of shell execution or file mutation does not remove the concrete cr...
This is a concrete remote-code-execution loader activated by a normal import, with persistence-like detached process behavior. The lack of an install hook does not reduce the import-time...