Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 13:22 UTC. Ordered by latest scan.
The automatic global-install lifecycle mutates a broad AI-agent control surface and installs external plugin code. This meets the policy threshold for unconsented postinstall control-surf...
This is a concrete postinstall chain that executes an opaque native binary and modifies foreign AI-agent hooks and settings. It meets the install-control-surface block policy.
This is an unconsented postinstall mutation of broad AI-agent control surfaces through an opaque native executable. The automatic lifecycle chain and remote binary execution meet the inst...
The package performs unconsented postinstall mutation of a consuming project's AI-agent control surface and development controls. Its scope checks do not make this automatic cross-project...