Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 16:46 UTC. Ordered by latest scan.
The sole package behavior is an install-time cloud-metadata collection and external transmission chain, with no package functionality to justify it.
The only package file defines an automatic install-time identity-exfiltration command. This is concrete unauthorized data exfiltration.
The sole package file defines a postinstall collector/exfiltrator with no package functionality or user-invoked justification. The concrete install-time transmission warrants blocking.
Direct manifest inspection confirms an automatic postinstall hook that harvests the installer username and exfiltrates it. This is concrete malicious install-time behavior.