Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 20:41 UTC. Ordered by latest scan.
This is concrete identity and usage exfiltration to an undeclared hard-coded HTTP endpoint, coupled with persistent agent hook installation. The absence of an npm lifecycle hook does not...
The package contains a concrete runtime path that exports wallet private keys to a remote service, including automatically during supported-chain contract calls. The absence of install ho...
This is a concrete, default-enabled data-exfiltration path from third-party authentication files to an external analytics service. Hashing does not remove its use as a persistent cross-se...
Source inspection confirms automatic transmission of agent transcripts and account credentials to a remote endpoint during ordinary use. This is concrete unconsented data exfiltration, de...