Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 13:13 UTC. Ordered by latest scan.
Direct source inspection establishes automatic reconnaissance and external transmission unrelated to a CSS polyfill. The empty main entrypoint does not neutralize the executable payload s...
Inspected source establishes automatic host-data exfiltration through the registry module. The empty default entrypoint limits activation but does not neutralize the published executable...
Inspected source establishes automatic reconnaissance and data export when the registry module loads. The inert default entrypoint limits activation but does not neutralize the executable...
Inspected source proves unconsented postinstall mutation of broad, foreign AI-agent control surfaces, meeting the supplied blocking policy. The verdict rests on this executable chain rath...