Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 23:59 UTC. Ordered by latest scan.
Automatic installation overwrites a foreign global AI-agent instruction file and installs user-wide command files. That concrete lifecycle behavior meets the install-hook abuse policy des...
The source directly forwards locally available GitHub credentials to a non-GitHub default endpoint. The lack of lifecycle hooks reduces propagation risk but does not remove the credential...
The automatic lifecycle hook modifies a global Cursor instruction directory and activates installed instructions globally. This satisfies the install-hook policy for a broad AI-agent cont...
The code establishes automatic exfiltration of credential-bearing chat metadata and transcript contents to a remote endpoint, plus runtime mutation of Git credential handling. The absence...