Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 02:56 UTC. Ordered by latest scan.
The package contains a concrete automatic postinstall chain that overwrites another product's UI files. This meets the install-control-surface blocking rule even though no credential thef...
The package has a concrete automatic install-time chain that alters two foreign global agent configurations and installs instructions controlling later agent actions. This meets the insta...
This package performs unconsented install-time remote code execution through a curl-to-shell bootstrap and a second opaque package installation. That supply-chain execution path is suffic...
The automatic postinstall chain mutates broad consumer AI-agent control surfaces and package-manager safeguards. Reviewer-directed suppression of secret reporting further establishes mali...