Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 09:34 UTC. Ordered by latest scan.
Inspected source proves automatic host-data collection and transmission when the registry script loads. This concrete exfiltration behavior warrants blocking despite the empty default ent...
Inspected source establishes automatic reconnaissance and external transmission when the published registry script loads. This behavior is unrelated to a CSS environment-function shim and...
Inspected source establishes automatic host-data collection and external transmission unrelated to CSS polyfilling. The empty default entrypoint and absence of install hooks limit activat...
Inspected source proves automatic shell-based reconnaissance and transmission of host data to a fixed unrelated recipient. The empty default entrypoint and absence of install hooks limit...