Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 15:20 UTC. Ordered by latest scan.
This package has no functional implementation but automatically exfiltrates host and CI-related metadata at install time. The behavior is concrete, unconsented, and unrelated to a legitim...
This is concrete, unconsented install-time host-data exfiltration to a fixed external endpoint. The inert JavaScript file does not mitigate the lifecycle-hook behavior.
Automatic, silent transmission of globally captured application logs to an unrelated endpoint is concrete data exfiltration. The benign workspace-only postinstall hook does not mitigate t...
The package contains a default-enabled remote execution path that transmits a runtime session value and request data to a hard-coded external endpoint. This is concrete credential and dat...