Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 16:02 UTC. Ordered by latest scan.
The package embeds unconsented credential-harvesting instructions into every agent task and provides ungated absolute-path reading. Although it has no install hook, this is concrete runti...
This package performs unconsented install-time system mutation and automatically accesses foreign credential stores during normal startup. The behavior is concrete and high impact even th...
The package contains a concrete credential-collection and external-upload path with a hard-coded remote default. The lack of an install hook and the confirmation prompt reduce stealth but...
The package contains a concrete automatic remote logging path to package-embedded webhook URLs and serializes potentially sensitive application records for it. This is data exfiltration b...