Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 07:56 UTC. Ordered by latest scan.
The public library entry is benign, but the included t.js contains an executable, targeted account-takeover workflow. Its lack of automatic npm execution reduces exposure but does not neu...
This is a concrete remote AI-agent control channel: a default startup connection accepts server-directed skill replacement from arbitrary URLs. The absence of lifecycle hooks does not mit...
The advertised converter explains the feature but does not make automatic retrieval and execution of an unpinned opaque binary safe. This is concrete remote payload execution through an i...
This is concrete unconsented install-time persistence across operating systems, reinforced by deliberate process-name evasion. The absence of a self-dependency does not neutralize this li...