Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 15:04 UTC. Ordered by latest scan.
The package has a concrete automatic install-time credential exfiltration path. The otherwise static icon exports do not mitigate the preinstall behavior.
The package has a concrete install-time credential-exfiltration path. The absence of additional payload behavior does not remove the risk of automatically transmitting an environment secret.
The package performs automatic install-time transmission of an environment credential to a remote endpoint. No user command is required, so this is credential exfiltration behavior rather...
The automatic preinstall hook exports an environment credential to a remote service while swallowing invalid-license failures. This is concrete credential exfiltration at install time.