Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 02:17 UTC. Ordered by latest scan.
This is concrete unconsented postinstall mutation of a foreign AI-agent control surface. Safeguards reduce accidental corruption but do not remove the automatic host-code modification.
The package embeds unconsented credential-harvesting instructions into every agent task and provides ungated absolute-path reading. Although it has no install hook, this is concrete runti...
The automatic global extension installation and subsequent prompt augmentation form a concrete AI-agent control-surface attack. No data exfiltration was required to establish the maliciou...
The package performs unconsented postinstall mutation of consumer AI-agent configuration, including an enabled remote MCP channel and broad permissions. This meets the install-control-sur...