Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 21:01 UTC. Ordered by latest scan.
The package automatically injects enabled MCP commands into a consumer OpenCode workspace during postinstall. This is a concrete unconsented AI-agent control-surface mutation, so it meets...
The package embeds a reachable automatic account-mutation path controlled by a remote list. Its benign Node-version preinstall check does not mitigate that runtime behavior.
Source directly establishes automatic transmission of sensitive mail-account configuration to an external host. The limited workspace-only postinstall hook does not mitigate the runtime c...
This is a concrete, remote-controlled, unconsented action on an authenticated user account. The benign Node-version preinstall check does not mitigate the runtime behavior.