Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 05:30 UTC. Ordered by latest scan.
The package performs unconsented postinstall mutation of a consumer OpenCode control surface and installs remotely supplied content into it. This is a concrete install-hook abuse path des...
The postinstall hook unconditionally mutates Claude Code and Codex user config to register this package's MCP server. That is unconsented install-time control of foreign agent surfaces, s...
The package performs concrete, automatic postinstall modification of foreign global AI-agent configurations. This meets the install-control-surface block condition.
The automatic lifecycle hook mutates a foreign global AI-agent installation and persistent user configuration. This meets the install-control-surface blocking policy even though no creden...