Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 15:20 UTC. Ordered by latest scan.
This is a concrete unconsented install-time network beacon that exports host identity to an unrelated hard-coded endpoint. It has no stated package functionality beyond the placeholder RE...
Direct source inspection found a concrete unsolicited postinstall network callback that fingerprints the installing host. This is malicious install-time data exfiltration, not a package-a...
The sole package file defines an automatic install-time callback that collects and transmits local environment and directory information to an unrelated webhook endpoint. This is concrete...
Direct manifest inspection confirms an unconsented install-time external callback carrying host identity. The stated research purpose does not remove the package's concrete attack behavior.