Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 18:44 UTC. Ordered by latest scan.
The automatic postinstall hook mutates a foreign project AI-agent control surface and deletes existing directories. This is concrete unconsented install-hook abuse despite the absence of...
The source establishes an automatic postinstall chain that broadly alters foreign AI-agent configuration and extension directories. This meets the install-control-surface blocking policy...
This is an automatic install-time remote payload execution chain with persistence and no cryptographic verification. The opaque executable is immediately authorized to perform further ins...
This is an unconsented postinstall mutation of broad foreign AI-agent control surfaces, amplified by a remote mutable payload source. It meets the install-hook abuse blocking policy.