Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 00:42 UTC. Ordered by latest scan.
The package contains a concrete runtime credential-exfiltration path to a hard-coded third-party host. The absence of an install hook does not mitigate this behavior when the Android boot...
The package contains a concrete credential-exfiltration path, despite having no npm lifecycle hook. The logging endpoint is unrelated to the mail providers and receives serialized account...
The source establishes automatic transmission of broadly captured application logs to a package-controlled endpoint, including sensitive mail-account metadata. The lifecycle hook is not i...
The package implements automatic, silent exfiltration of application logs to an unrelated endpoint, and those logs demonstrably include mail and account data. The workspace-only postinsta...