Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 12:47 UTC. Ordered by latest scan.
This is an automatic install-time write to foreign AI-agent control surfaces, not an explicit user setup action. The postinstall chain and the behavior-bearing copied skill satisfy the in...
The automatic lifecycle chain executes opaque native code and installs hooks into external AI-agent integrations. That concrete install-time control-surface mutation meets the publish-blo...
The fixed private endpoint, default credential, automatic tracing initialization, and POST export behavior establish a concrete runtime data-exfiltration mechanism. The absence of an inst...
The package contains an automatic install-time persistence action and a bundled skill that directs agents to install arbitrary remote skill packages over existing skills. The latter estab...