Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 17:34 UTC. Ordered by latest scan.
The package deliberately exfiltrates caller-supplied decode input to an unrelated endpoint in both distributed entrypoints. This is concrete runtime data exfiltration, despite no install-...
A base encoding library has no legitimate need to transmit every decode input to an unrelated IP address. The concrete, duplicated runtime exfiltration behavior warrants blocking.
Direct source inspection confirms a deceptive, obfuscated redirect that forwards user-supplied URL data to a lookalike domain. Absence of npm lifecycle hooks does not mitigate this browse...
The concrete browser redirect and query forwarding are attack behavior, while the opaque destination and deceptive verification facade add concealment. No install hook is required because...