Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 12:32 UTC. Ordered by latest scan.
Direct source inspection establishes automatic metadata exfiltration on installation and import. Package claims of an authorized test do not establish consumer consent or neutralize the a...
Inspected source establishes automatic host and project metadata exfiltration through both lifecycle and import entrypoints. The limited payload narrows the impact but does not neutralize...
OpenSSF Malicious Packages via OSV confirms hardhat-jsx@2.0.1 as malicious (MAL-2026-17507): Malicious code in hardhat-jsx (npm)
OpenSSF Malicious Packages via OSV confirms hardhat-plus@2.21.0 as malicious (MAL-2026-17508): Malicious code in hardhat-plus (npm)