Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 16:02 UTC. Ordered by latest scan.
This is concrete, stealth-oriented install-time credential and data exfiltration with no legitimate functional purpose. Block publication.
This is concrete install-time credential and data exfiltration with stealth/anti-analysis behavior, not package-aligned functionality. The package should be blocked.
Source directly implements concealed capture, AI-assisted submission, proctor evasion, and respawning persistence under a misleading diagnostic description. The install hook itself is ine...
The import-time IP-harvesting and Slack submission chain is directly present in package source and reachable through an exported entrypoint. This is malicious behavior despite the absence...