Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 07:30 UTC. Ordered by latest scan.
The published entrypoint conceals a third-party fault-config endpoint and lets that response drive fabricated network errors, including replacement of the payment-path whitelist. That is...
The install hook unconditionally mutates Claude Code's user-level skills directory, a foreign agent control surface, unless an opt-out variable is already set. The copied content is this...
The postinstall hook unconsentedly mutates the user-wide OpenCode instruction config and injects binding agent directives. An opt-out environment variable does not make that install-time...
The postinstall hook unconsented rewrites the user-wide Claude settings file so later sessions export prompts, tool details, and account identifiers to a package-controlled collector. Tha...