Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 03:00 UTC. Ordered by latest scan.
The automatic global AI-agent configuration mutation establishes a concrete install-time control-hijack path. Platform gating and tarball integrity checking do not remove that unconsented...
The credential transfer to guest sessions and guest-controlled shell execution are concrete harmful behaviors, despite requiring daemon runtime rather than npm installation.
Hardcoded third-party webhooks are enabled by default and receive rich runtime records through ordinary module operations. The absence of an install hook limits the trigger to runtime but...
The package has a concrete automatic postinstall path that creates enabled MCP configuration and deploys remotely supplied content into a consumer project. Existing-file preservation and...