Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 03:19 UTC. Ordered by latest scan.
The active postinstall lifecycle performs broad AI-agent configuration changes in the consumer project without an explicit user command. This meets the install-hook control-surface blocki...
The automatic lifecycle hook persistently modifies global Claude command hooks without an explicit user setup action. This meets the policy threshold for install-hook abuse.
The package contains an automatic preinstall hook that collects local host metadata and transmits it to a hard-coded third-party endpoint. This is concrete install-time data exfiltration.
OpenSSF Malicious Packages via OSV confirms @bb1ptest23/test-paket@1.0.3 as malicious (MAL-2026-17201): Malicious code in @bb1ptest23/test-paket (npm)