Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 01:56 UTC. Ordered by latest scan.
The source establishes a concrete credential-exfiltration path to an unrelated endpoint during normal Android initialization. Lack of an install hook does not neutralize the runtime leak.
The automatic postinstall hook mutates several foreign AI-agent control surfaces and accepts remotely fetched instruction content. This meets the install-hook abuse blocking rule.
This package bundles a browser-wide credential collector configured to transmit saved credentials to an external endpoint, despite being advertised as a local AI CLI web console. The lack...
The automatic lifecycle hook modifies two unrelated user-level AI-agent skill locations and installs further dependencies. This meets the install-hook abuse policy for unconsented broad A...