Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 16:02 UTC. Ordered by latest scan.
This is automatic, concealed DNS exfiltration during installation and import, unrelated to the advertised link utility. The encoded implementation and lifecycle trigger establish concrete...
The package automatically combines a hard-coded external receiver with parent authentication and a mount-time request. The override does not remove the unsafe default path.
This package uses automatic install hooks to exfiltrate local environment metadata to an external service. That is concrete unconsented install-time data collection.
This package contains an enabled default external logging receiver that transmits runtime data, including supplied scan codes, to embedded webhook URLs. The absence of an install hook doe...