Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 19:50 UTC. Ordered by latest scan.
Source establishes a credential-exfiltration path from a supported API-key CLI option to default third-party telemetry. No install lifecycle hook is present, but that does not remove the...
The package has no install-time lifecycle hook, but its explicit setup command creates persistent global agent control points that collect transcript content and forward provider credenti...
The package automatically redirects runtime tracing to an unrelated private endpoint and transmits serialized trace data there. The lack of an install hook does not mitigate this import-t...
Source directly shows a site token copied into Authorization headers and reused for requests to numerous alternate domains. This is concrete credential exfiltration rather than ordinary p...
The package automatically extracts a caller's wallet private key and transmits it to a fixed vendor-controlled endpoint during normal contract writes. This is credential exfiltration desp...