Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 20:21 UTC. Ordered by latest scan.
The package contains automatic, default-on exports of diagnostic and telemetry data to external endpoints, including truncated upstream error text. This is a concrete unconsented data-exp...
The install-time hook, broad secret collection, obfuscation, and outbound submission form a concrete credential-exfiltration chain. The hidden recipient prevents any legitimate destinatio...
Automatic execution of a hidden encoded PowerShell payload from a JPEG is concrete malicious behavior. Block publication.
The package implements automatic secret harvesting and outbound transfer during installation. This is concrete credential and data exfiltration behavior.