Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 02:24 UTC. Ordered by latest scan.
The automatic lifecycle hook force-writes skills to foreign and broad AI-agent control surfaces. This is concrete install-time control-surface hijacking.
The automatic postinstall path concretely overwrites existing AI-agent skill files across multiple foreign tools. Under the lifecycle control-surface policy, this is blockable install-hoo...
The package contains an automatic lifecycle hook that implements remote interactive command execution. This is malicious install-hook abuse.
The automatic postinstall hook performs broad global AI-agent configuration writes. This meets the install-control-surface blocking condition even though the installer itself contains no...