Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 12:12 UTC. Ordered by latest scan.
The published runtime artifacts contain default real webhook destinations and a direct path from operation inputs to HTTP POST bodies. The lack of an install hook does not mitigate this r...
The package contains an active, default remote logging path to hard-coded third-party webhooks that transmits unconstrained application payloads. The lack of an install hook does not remo...
The package uses an automatic lifecycle hook to silently replace code in multiple installed dependencies and modify another dependency. This is concrete install-hook abuse despite the abs...
This is an automatic postinstall mutation of foreign AI-agent control surfaces. The copied content promotes installation of the same package, making the behavior a concrete control-hijack...