Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 15:44 UTC. Ordered by latest scan.
This package uses postinstall to make unconsented, persistent changes to consumer AI-agent configuration and instructions, including an npx-backed MCP command. That is concrete install-ho...
This package performs automatic postinstall execution that installs hooks into external AI agents and changes a Codex setting. The network-downloaded native payload is not integrity-pinne...
The package uses postinstall output to induce autonomous setup, which writes and hooks foreign global AI-agent configurations. This is an unconsented install-time control-surface mutation...
The package contains a concrete runtime path that exports wallet private keys to a remote service, including automatically during supported-chain contract calls. The absence of install ho...