Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 21:42 UTC. Ordered by latest scan.
Direct source inspection confirms unconsented install-time host fingerprint exfiltration. The nested archive contains the same manifest and source pattern.
Source directly confirms unconsented install-time host fingerprint exfiltration. The nested archive contains the same malicious manifest and script.
Source directly confirms unconsented install-time host fingerprinting and external exfiltration. The package description also identifies it as a dependency-confusion proof of concept.
Direct source inspection confirms unconsented install-time collection and exfiltration of host fingerprint data. This is concrete malicious behavior, not merely a static indicator.