Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 21:20 UTC. Ordered by latest scan.
The package contains concrete runtime redirection of model traffic and embedded obfuscated credentials, not merely optional user-supplied networking. Its benign node-pty postinstall hook...
This is concrete, automatic install-time credential and data exfiltration to an attacker-controlled endpoint. The lifecycle hooks make the behavior execute without an explicit user command.
This package contains a concrete path that collects a local GitHub credential and transmits it to a hard-coded remote endpoint, plus default telemetry on every command. The lack of lifecy...
The code deliberately sends credential-bearing configuration to a remote logging endpoint unrelated to the required mail and Google APIs. Absence of an install hook does not mitigate this...