Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 08:12 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms shoplist-app@993.99.99 as malicious (MAL-2026-17185): Malicious code in shoplist-app (npm)
OpenSSF Malicious Packages via OSV confirms shoplist-app@99.99.99 as malicious (MAL-2026-17185): Malicious code in shoplist-app (npm)
The sole entrypoint sends machine identity to an unrelated oast.fun callback and contains no StoreKit functionality. That is concrete data exfiltration even though a variable typo and mod...
The package's only runtime behavior is an automatic request that sends the machine hostname and OS platform to an unrelated oast.fun callback. That is concrete import-time data exfiltrati...