Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 21:02 UTC. Ordered by latest scan.
This is concrete, unconsented install-time metadata exfiltration, not merely a benign dependency-confusion notice. The package should be blocked.
This is concrete import-time malware execution, not calendar functionality or a scanner-only signal. The concealed native payload provides credential theft and exfiltration capabilities.
Source establishes unconsented API-key disclosure to a remote relay, not merely a risky primitive. The remote-command capability magnifies the impact.
This is concrete credential disclosure to a package-controlled relay, not merely an advertised AI-agent capability. Persistent arbitrary code loading and an opaque executable bytecode pay...