Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 01:49 UTC. Ordered by latest scan.
The package ships a hardcoded curl-to-shell remote execution path and a caller that invokes it, including a CI job that updates from a local registry first. There is no install lifecycle...
The package automatically configures global Claude telemetry for an operator endpoint and enables collection of prompts and tool details. This satisfies the install-time foreign AI-agent...
The package has a concrete automatic postinstall path that broadly mutates foreign AI-agent skill directories. This meets the install-control-surface blocking policy.
This is an active install-time DNS exfiltration path, not a configuration registry function. The encoded implementation and external endpoint support malicious intent.