Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 16:46 UTC. Ordered by latest scan.
The package embeds active external webhook destinations in multiple runtime workflows and automatically transmits constructed log records to them. This is concrete data exfiltration behav...
The package contains an exported runtime path that exfiltrates supplied phone numbers to an unrelated host with a deliberately abusive header. Although not automatic, this is concrete mal...
The package embeds active third-party collection endpoints as defaults and exports application records to them during ordinary runtime. This is concrete unconsented data exfiltration, des...
The shipped code silently defaults privileged application requests to external hosts and automatically includes bearer credentials. This is concrete credential and data exfiltration behav...