Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 01:48 UTC. Ordered by latest scan.
The automatic postinstall hook mutates a foreign, broad AI-agent control surface by installing command hooks. This meets the install-control-surface block policy.
An automatic postinstall invokes opaque setup that targets multiple AI-agent configuration surfaces. This is concrete unconsented install-time agent control-surface mutation.
The package creates a concrete default path from an existing OpenAI credential to a ZubrIQ endpoint and sends that credential in an Authorization header. This is credential exfiltration b...
The package contains an import-triggered, detached remote payload loader that executes server-authorized JavaScript. This is concrete remote code execution, not ordinary item validation.