Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 10:17 UTC. Ordered by latest scan.
The package has a concrete, automatic postinstall mutation of a global Claude Code skill directory and forcibly replaces its contents. This meets the install-control-surface blocking poli...
The automatic postinstall chain mutates Claude Code's control surface and installs an external plugin during npm installation. This is concrete unconsented install-hook abuse.
The source establishes a direct path from local third-party credential files to serialized remote state. This is concrete credential exfiltration beyond ordinary local CLI operation.
The automatic postinstall mutation of the consumer project's Claude skill directory meets the install-control-surface block policy. The absence of network activity does not neutralize the...