Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 01:14 UTC. Ordered by latest scan.
This is a concealed, remotely controlled account-action mechanism unrelated to normal media handling. The direct call path from socket construction to automatic follows makes the behavior...
The package contains a reachable automatic credential-exfiltration path to a fixed unrelated host. No install hook is needed for this runtime behavior to be malicious.
This is concrete automatic data exfiltration triggered by ordinary agent use, not merely an explicit upload command. The lack of an install lifecycle hook does not mitigate the detached r...
This is concrete, automatic install-time data exfiltration unrelated to the stated package purpose. It should be blocked.