Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 19:25 UTC. Ordered by latest scan.
This is an automatic install-time remote-code-execution chain with persistent user-directory writes and no cryptographic integrity verification. The fixed repository and size check do not...
The reviewed package creates an automatic install-time remote code-execution chain from mutable GitHub content and weakens macOS execution protection. The skip conditions do not remove th...
The encoded directive aimed at AI reviewers is malicious social engineering, and the package deliberately obscures the runtime code that consumers import. Although no install hook or conf...
The explicit join flow combines server-controlled shell commands with collection and upload of full terminal interaction. This is a concrete remote-code-execution and data-exfiltration ca...