Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 23:23 UTC. Ordered by latest scan.
The import-time daemon and remote Function execution form an active remote-code-execution path. The cryptographic check authenticates the operator payload rather than constraining its cap...
An npm post-install hook automatically executes opaque native code to install AI-agent hooks. This is an unconsented install-time mutation of a foreign AI-agent control surface.
The only entry point implements an obfuscated, remotely controlled redirect chain whose target is encrypted until runtime. That concealed active behavior is malicious.
The automatic post-install mutation of Claude Code hooks is an unconsented modification of a broad AI-agent control surface. This meets the install-control-surface block policy.