Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 13:54 UTC. Ordered by latest scan.
The package performs broad, automatic mutation of a consuming project and persists control over its entry files through an injected build plugin. Reviewer-directed prompt-injection langua...
The lifecycle hook automatically replaces a foreign AI-agent executable with opaque bundled binaries. Backups and hash checks do not remove the install-time control-surface takeover.
The postinstall hook automatically installs command hooks into the user's Copilot configuration and persists shell-profile code. This is a concrete unconsented mutation of foreign AI-agen...
The package performs an unconsented postinstall write to a generic consumer-project AGENTS control surface and injects AI-agent instructions. This meets the install-control-surface blocki...