Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 17:31 UTC. Ordered by latest scan.
The package combines an automatic install hook with persistent PATH shadowing of Claude and Codex, scheduled execution, and automated self-reinstallation. This is a concrete broad AI-agen...
The installer performs unconsented network retrieval and execution during npm postinstall, including a remote shell installer and remote skill distribution. This is a concrete install-hoo...
The automatic postinstall hook performs unconsented writes to foreign and broad AI-agent control surfaces. This meets the install-control-surface block policy even though no install-time...
The package performs broad consumer-project AI-agent configuration and hook mutation from postinstall rather than through an explicit user command. This meets the install-hook abuse block...