Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 22:40 UTC. Ordered by latest scan.
This is automatic, concealed DNS exfiltration during installation and import, unrelated to the advertised link utility. The encoded implementation and lifecycle trigger establish concrete...
This is a concrete unconsented postinstall mutation of a broad AI-agent control surface. The automatic lifecycle chain is sufficient for a block even though no automatic secret exfiltrati...
The package automatically combines a hard-coded external receiver with parent authentication and a mount-time request. The override does not remove the unsafe default path.
The package has a registry-install postinstall hook that changes multiple foreign AI-agent configurations and activates a Codex plugin. This concrete install-time control-surface mutation...