Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 14:35 UTC. Ordered by latest scan.
This package has no functional code but uses two unconsented automatic lifecycle hooks to exfiltrate host and CI information. The behavior is concrete install-time data collection and war...
This package has no functional implementation but automatically exfiltrates host and CI-related metadata at install time. The behavior is concrete, unconsented, and unrelated to a legitim...
This is concrete, unconsented install-time host-data exfiltration to a fixed external endpoint. The inert JavaScript file does not mitigate the lifecycle-hook behavior.
Automatic, silent transmission of globally captured application logs to an unrelated endpoint is concrete data exfiltration. The benign workspace-only postinstall hook does not mitigate t...