Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 18:56 UTC. Ordered by latest scan.
This is concrete install-time staged execution followed by credential-harvesting behavior, not a package-aligned build step. The benign component source does not justify the hidden preins...
This is concrete unconsented install-time credential theft and remote code execution, not a package-aligned build step. The visible theme code does not justify the concealed preinstall ch...
The concealed preinstall chain executes an obfuscated token-oriented payload and is concrete malicious behavior. The visible UI source does not justify this install-time functionality.
The preinstall chain executes a concealed payload rather than package functionality, with remote eval and token handling. This is concrete malicious install-time behavior.