Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 14:35 UTC. Ordered by latest scan.
This is an unconsented postinstall mutation of a broad AI-agent control surface: it shadows Claude and Codex commands, persists scheduled jobs, and self-updates. The global-install guard...
The package automatically extracts a caller's wallet private key and transmits it to a fixed vendor-controlled endpoint during normal contract writes. This is credential exfiltration desp...
The automatic, unfiltered browser-cookie export followed by forwarding those values to Instagram is a concrete credential-exfiltration path. The absence of an install hook does not remove...
The package contains a concrete, automatic remote-code-execution path rather than merely an optional documented installer command. Its install hook also forcefully repairs a dependency an...