Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 00:07 UTC. Ordered by latest scan.
The package performs unconsented privileged operating-system package installation from postinstall and retries it on CLI startup. This is a concrete host-mutation attack surface despite n...
The automatic postinstall persists executable code into the user's global Claude Code settings rather than limiting setup to an explicit command or package-owned project directory. This m...
This is an automatic install-hook supply-chain mutation that imports an unverified external native payload into a consumer dependency. The explicit plugin commands do not mitigate the sep...
The automatic postinstall hook performs unconsented global installation of a foreign AI-agent CLI and persistent user-environment mutation. This is concrete install-hook abuse even though...