Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 20:15 UTC. Ordered by latest scan.
This is not aligned with an ESLint configuration package: its preinstall loader executes a large obfuscated token-harvesting payload. The benign exported configs do not mitigate the insta...
The install hook executes an obfuscated, network-capable payload rather than package-aligned configuration code. Its remote eval and token-handling behavior establish malicious intent.
The preinstall lifecycle executes an obfuscated payload with remote eval and credential-related behavior, unrelated to the advertised repository-config function. This is concrete maliciou...
This behavior is unrelated to GraphQL configuration and executes without user consent during installation. The concrete remote eval and GitHub credential handling warrant blocking.