Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 01:10 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms @mr-supun-fernando/supunmd-bail@3.0.3 as malicious (MAL-2026-16387): Malicious code in @mr-supun-fernando/supunmd-bail (npm)
Postinstall unconditionally mutates the user-wide Claude Code control surface and enables prompt and tool telemetry to a package-controlled collector. That is unconsented install-time age...
The postinstall path is an automatic global-install write into Claude Code's broad settings and hook surface, including tool-use interceptors and a third-party plugin pin. Opt-out flags a...
The postinstall hook unconditionally replaces directories in the consumer project's .claude/skills with a package-supplied Claude skill that auto-triggers on generic UI requests. That is...