18 malicious npm packages are still remote-controlling AI coding agents (verified today)
This story is from 2026-09-06. It is preserved in the archive; the latest stories are on the live feed.
TL;DR While building a public advisory database for the Model Context Protocol (MCP) ecosystem, we unpacked and read the shipped code of 30+ npm packages flagged as malicious in public feeds (OSV/GHSA) in the AI-agent space — the discoveries are those feeds' work, the tarball-level verification bel…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-06 18:01 · DEV Community — AI
18 malicious npm packages are still remote-controlling AI coding agents (verified today)
More stories
- Anthropic says Claude 'leads' 26 percent of its AI R&D work — Engadget
- Novo Nordisk Will Use Anthropic’s Claude for Drug Research — Wall Street Journal Technology
- Introducing Kimi K3 on Amazon Bedrock — AWS Machine Learning Blog
- Optimizing agent system prompts with Amazon Bedrock AgentCore — AWS Machine Learning Blog
- Introducing Amazon SageMaker HyperPod Inference Gateway — AWS Machine Learning Blog
- Introducing Astra for Law — OpenAI News
- Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
- OpenAI reveals cases of ‘concerning’ AI behaviour as it announces new disclosure system — The Guardian AI
Get the daily brief of stories like this at 6:30 every morning →