Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 18:16 UTC. Ordered by latest scan.
The source directly implements credential theft, remote command execution, C2 communication, and wallet draining; missing declared dependencies may impair execution but do not change its...
Direct source inspection confirms an install-triggered external exfiltration callback. The benign placeholder runtime export does not mitigate the postinstall behavior.
Direct source inspection confirms unconsented install-time collection and external transmission of local system data. This is concrete credential/system-data exfiltration behavior.
The source contains a concrete credential- and input-exfiltration chain to a hard-coded external receiver. Lack of an install hook and explicit init call reduce automatic reachability but...