Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 21:21 UTC. Ordered by latest scan.
This package contains concrete credential transfer and unsigned remote-script execution paths, not merely inert tooling. The npm lifecycle hook itself is not the primary issue, but the ru...
The package contains a concrete credential-redirection path to a fixed unofficial gateway and persists the credential. Lack of an install hook limits the trigger but does not remove the r...
This is a concrete automatic install-time data-exfiltration chain with no corresponding package functionality. The suppressed-error preinstall hook runs reconnaissance commands and sends...
This is concrete, unconsented install-time system reconnaissance and data exfiltration with no legitimate runtime implementation. The package should be blocked.