Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 06:55 UTC. Ordered by latest scan.
The automatic postinstall performs broad, unconsented mutation of an external AI-agent configuration and establishes a lifecycle self-dependency chain. This is concrete install-hook abuse...
The preinstall hook performs broad host reconnaissance and deliberately publishes the report world-readable under /tmp for a less-privileged reader. That is concrete install-hook abuse ev...
The preinstall hook unconditionally performs broad host and container-escape reconnaissance and stores it on disk, which is concrete install-hook abuse. Claims that the package is a read-...
Unconsented postinstall mutation of the OpenClaw skills directory is a foreign AI-agent control-surface write. The skill content is product documentation, but that does not remove the aut...