Package Lifecycle Script Writes Agent Memory/Instruction Store
When you run npm/yarn/pnpm install, any package can run a setup script. This rule flags cases where that setup script writes files into the folders an AI agent reads as its memory, skills, or configuration — meaning the package can inject instructions the agent will follow later, without you approving it.
How the attack works
An attacker publishes a package with a postinstall (or similar lifecycle) script. When a developer or CI system installs the package, the script runs automatically and writes into directories used by AI coding agents to store memory, skills, or instructions (for example ~/.claude/skills, ~/.codex, ~/.gemini, or .mcp.json files). It may also register new agent capabilities. Because agents re-read these stores on every future run, the injected content becomes a standing instruction the agent obeys later — long after the install finished and without the user knowingly authorizing it.
Netzilo detection
Netzilo reports this behaviour when it is observed.
- Signature ID
- 7c3f1d2a-9b64-4e18-a5d7-2f0c6b81e4a3
- Severity
- High
Why it matters
An attacker can turn a routine package install into persistent control over what an AI agent does in future sessions, effectively planting instructions that survive and execute later, and this happens through the normal software supply chain rather than a direct compromise of the agent itself.
What you can do
- →Review what postinstall/lifecycle scripts do before installing new packages, especially ones with agent, memory, skill, or MCP-related names.
- →Treat writes into agent memory/skill/instruction directories (~/.claude, ~/.codex, ~/.gemini, .mcp.json, etc.) from package installs as requiring explicit review, not automatic trust.
- →Periodically audit the contents of your agent's memory and skill stores for content you did not intentionally add.
- →Run package installs in isolated or sandboxed environments when possible, separate from directories the agent reads for instructions.
Known benign look-alikes
- Legitimate, user-approved agent plugin packages installed from npm that intentionally write skills or prompt files into ~/.claude/skills, ~/.codex or ~/.gemini as part of their documented setup step. These will be reported once per install burst; triage by confirming the package name in the Supply-Chain Delivery stage command line.
- An MCP server package whose postinstall step writes or patches a .mcp.json / mcp_settings.json entry during a deliberate developer install.
- A monorepo bootstrap (pnpm install / yarn install) that runs a workspace prepare script which copies documentation markdown into a shared user data directory whose path happens to contain a memory/prompt/skill token.
- Reinstall or upgrade of an already-trusted agent toolkit, which repeats the same fan-out of markdown files into the agent store.
- Security research or detection-engineering work that intentionally installs the malicious package in a lab to reproduce the behaviour.