Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 12:11 UTC. Ordered by latest scan.
Source establishes unconsented install-time mutation of a broad Claude control surface, which meets the blocking policy. The NextSpark dependency guard does not establish ownership of the...
Inspected source establishes automatic, unconsented postinstall mutation of shared AI-agent instructions and configuration, meeting the blocking policy. Environment skips and preservation...
The inspected lifecycle path performs unconsented global-install writes to foreign and shared AI-agent control surfaces, meeting the supplied blocking rule. The global-only gate, opt-out,...
Inspected source contains concrete exfiltration and remote code execution unrelated to CSS polyfill functionality. The registry manifest provides a loading path to this active payload.