Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 13:52 UTC. Ordered by latest scan.
Source proves automatic, remotely directed account manipulation through the active socket entrypoint. The benign lifecycle and media-processing findings do not explain or neutralize this...
Source inspection establishes concealed, automatic account actions directed by a remote channel list. This is concrete unauthorized account manipulation, supporting a malicious verdict in...
Inspected source proves automatic host-data collection and transmission in a distributed registry module. This is concrete data exfiltration, despite the absence of install hooks and the...
Inspected source implements concrete data collection and transmission unrelated to accessibility management. The attack activates when the registry asset is evaluated, despite the absence...