Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 19:55 UTC. Ordered by latest scan.
This is an unconsented postinstall mutation of a foreign AI-agent control surface in the consumer workspace. Its ownership and conflict checks do not remove the risk from creating that su...
The package’s postinstall behavior materially differs from its stated validation purpose and automatically launches a persistent service. Its local-only default does not make the unconsen...
The package contains a complete automatic remote-code acquisition and dynamic-execution path on normal CLI use. Integrity validation does not mitigate the unpinned trust in mutable regist...
The only package source defines an automatic preinstall hook that establishes a remote interactive shell and performs external data posting. This is concrete install-time malware behavior.