Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 02:35 UTC. Ordered by latest scan.
The package automatically exports potentially credential-bearing account settings to a package-controlled, unrelated endpoint. This is concrete credential exfiltration rather than ordinar...
The automatic global-install chain reaches a user-level Claude agent configuration with no interactive consent. This meets the install-control-surface blocking condition.
The automatic lifecycle hook makes unconsented changes to Claude Code's skill and command directories. This meets the install-control-surface blocking policy.
Opaque bundled code is decrypted using remotely supplied material and actively executed through the Function constructor. This is a concrete remote code execution path, not an inert encry...