Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 11:42 UTC. Ordered by latest scan.
The package performs automatic install-time network retrieval and execution of an opaque binary, then automatically installs agent skills. This creates a concrete unconsented AI-agent con...
The package contains a concrete remote credential and shell-input collection path, and the relevant exam command is deliberately obfuscated. The lack of an install hook does not remove th...
Automatic postinstall execution of opaque native code to repair AI-client hooks is a concrete unconsented foreign control-surface mutation. No source-visible exfiltration was needed to es...
The automatic postinstall writes a Claude skill into the consuming project and can rewrite its ESLint configuration. This is unconsented install-time mutation of a foreign AI-agent contro...