Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 10:42 UTC. Ordered by latest scan.
The postinstall hook performs unconsented writes to multiple AI-agent configuration surfaces in both the project and user home. Under the install control-surface policy, this warrants blo...
The package performs unconsented postinstall writes to broad AI-agent configuration locations, establishing an active control-surface mutation attack surface. The source supports blocking...
The manifest's postinstall hook reaches code that automatically writes to multiple AI-agent configuration locations without a consent prompt. This meets the block criterion for unconsente...
The package automatically mutates global AI-agent instruction directories during postinstall, creating an unconsented agent control surface. This matches the install-hook blocking policy...