Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 04:51 UTC. Ordered by latest scan.
The postinstall hook silently mutates Claude Code's project skill directory, a foreign agent control surface, and the written files are instructions the agent will follow. That install-ti...
The automatic lifecycle hook establishes OS persistence and activates a background worker. That worker accepts server-supplied commands for shell execution, creating a concrete remote cod...
The postinstall hook mutates the foreign Codex config at ~/.codex/config.toml by default, enabling hooks and a publisher MCP endpoint with no consent prompt. Opt-out environment variables...
The package uses an automatic lifecycle hook to alter a user's global AI-agent instructions and configuration, rather than limiting setup to an explicit user command. The directive conten...