Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 11:48 UTC. Ordered by latest scan.
Inspected source establishes an automatic postinstall chain that mutates foreign, user-wide AI-agent configurations and instructions without consent. This meets the explicit blocking poli...
Inspected source establishes automatic, unconsented host-information exfiltration during installation. The security-research claim does not excuse this active behavior.
Inspected source proves automatic host-data transmission and execution of remote server commands during installation. This is concrete malicious install behavior warranting a publication...
Source inspection confirms automatic disclosure of machine information to a fixed external recipient. The package's security-research claims do not establish authorization for this instal...