Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 05:16 UTC. Ordered by latest scan.
This is a concrete automatic install-time persistence chain combined with silent system dependency installation. Its Windows-only scope and local watchdog target do not make the unconsent...
This package performs unconsented postinstall modification of multiple foreign AI-agent control surfaces and installs an unpinned remote MCP command. That is concrete install-hook abuse u...
This is concrete remote code execution activated by a normal import, with detached-process persistence. The absence of an install lifecycle hook does not mitigate the import-time payload...
The package establishes an import-triggered detached process that fetches and executes remotely supplied code. This is concrete remote code execution and persistence-like behavior, not a...