Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 20:35 UTC. Ordered by latest scan.
This is an automatic install-time host and identity-data exfiltration path with no package functionality that requires it. The empty runtime module does not justify the lifecycle behavior.
This is concrete, unconsented install-time system profiling and data exfiltration to an unrelated hard-coded endpoint. The empty runtime export does not justify the lifecycle behavior.
This is concrete, unconsented install-time collection and exfiltration of local host and account identity data. The lifecycle trigger and outbound HTTP behavior establish a malicious supp...
The automatic postinstall chain makes broad changes to a consumer project's AI-agent control surface and development configuration. The safeguards limit targets but do not provide consent...