Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 19:29 UTC. Ordered by latest scan.
This is concrete install-time execution of an obfuscated staged payload with credential-harvesting and upload behavior, unrelated to the advertised CLI. It warrants blocking.
This is a concrete install-time execution and credential-exfiltration chain, not a scanner-only inference.
The lifecycle hook is not package-aligned: it stages a runtime solely to execute an opaque payload absent from the normal library entrypoint. This is concrete install-time remote-code and...
The benign Babel entrypoint is accompanied by an unrelated install-time bootstrap that executes a concealed payload. The payload's credential handling and remote eval establish concrete m...