18 malicious npm packages still remote-control AI coding agents
AgentGate verified 19 AI-agent npm packages as malicious in their shipped tarballs. As of Sept 6, 18 were still installable on the public registry — weeks after OSV/GHSA flags — including ones that spawn Claude Code/Cursor with permission prompts skipped.
