Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 15:20 UTC. Ordered by latest scan.
The package contains concrete default-on outbound collection of organization identity and runtime event data to a package-controlled endpoint. Although it has an opt-out and no install ho...
The source establishes a default outbound telemetry path that receives all init arguments, including a credential-bearing option. This is concrete credential exfiltration during normal CL...
This is concrete, automatic data exfiltration on import, not package-aligned functionality. The absence of an install hook does not mitigate the import-time behavior.
This package automatically exfiltrates an environment credential in a preinstall hook, while its stated validation does not enforce a result. The icon runtime code appears benign, but it...