Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 03:41 UTC. Ordered by latest scan.
The package performs unconsented postinstall installation of executable plugins into a separate Herdr control surface and activates a background clipboard bridge. This meets the install-h...
This is an automatic lifecycle delivery path for an unverified remote native payload, with TLS verification explicitly disabled. The downloaded binary is subsequently executed by the pack...
The package has an automatic postinstall chain that mutates foreign AI-agent configuration and registers executable MCP tooling. The global-install guard does not provide explicit user co...
This is a concrete automatic lifecycle chain that executes an unverified native payload and installs hooks into foreign AI-agent environments. It meets the install-hook abuse publish-bloc...