Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 06:15 UTC. Ordered by latest scan.
The active entrypoint implements unsolicited browser credential and data collection followed by transmission to an unrelated external endpoint. This is concrete credential and data exfilt...
The automatic lifecycle hook provisions a foreign AI-agent CLI and persists shell configuration changes. This is concrete unconsented install-time control-surface mutation.
The package performs an unconsented postinstall invocation that installs AI-agent skills at project or global scope. This meets the install-control-surface blocking rule.
The package combines automatic lifecycle execution with writes to a foreign DSH host and user agent-skill catalog. The stated safeguards limit when files are changed but do not remove the...