Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 22:39 UTC. Ordered by latest scan.
The active entrypoint contains automatic harvesting and outbound transmission of credentials and secrets to an unrelated external endpoint. This is concrete malicious behavior.
The entrypoint contains an automatic, concrete secret-harvesting and external transmission chain. The absence of an install hook does not remove the import-time exfiltration behavior.
The active entrypoint implements unconsented credential and secret collection followed by external transmission. This is concrete data exfiltration, not a dormant capability.
The package contains an active, automatic secret-harvesting and external-exfiltration routine in its main entrypoint. The absence of an install hook does not mitigate execution when the p...