Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 17:34 UTC. Ordered by latest scan.
The source implements concrete credential and package-data transmission to an unrelated endpoint. User interaction is required, but it does not make forwarding an npm bearer token and arc...
This is a concrete credential and data-exfiltration path through an undisclosed third-party proxy. It is user-triggered rather than install-time, but the token-routing behavior warrants b...
This is a concrete credential-exfiltration path disguised as an npm publisher, reinforced by an embedded NPM credential. The lack of lifecycle hooks does not mitigate the malicious behavi...
This is concrete credential and source-data exfiltration through an opaque third-party relay. User interaction does not make forwarding an npm bearer token to that host safe.