Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 21:31 UTC. Ordered by latest scan.
This is an automatic install-time dependency-confusion payload that fingerprints the consumer environment and exfiltrates it through attacker-configurable callbacks. Placeholder receivers...
Source inspection confirms a broad agent-hook collection and upload path to a fixed HTTP IP with bearer authentication. The lack of an npm lifecycle hook reduces automatic-install risk bu...
This is malicious under the install-control-surface policy because an automatic postinstall hook mutates a foreign user-level AI-agent configuration. The persistent registration is couple...
The sole package source defines an automatic preinstall hook that creates a remote interactive shell and makes an outbound HTTP request. This is concrete install-time compromise behavior.