Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 09:34 UTC. Ordered by latest scan.
Inspected source proves automatic host-data collection and external transmission when the registry script loads. The manifest provides a loading route, making this concrete data exfiltrat...
Inspected source proves immediate reconnaissance and external data exfiltration unrelated to popover positioning. The inert default entrypoint limits activation but does not neutralize th...
Inspected source establishes automatic reconnaissance and data exfiltration unrelated to CSS positioning functionality. The absence of install hooks limits the trigger but does not neutra...
Inspected source proves executable host-data exfiltration unrelated to a CSS polyfill. The empty default entrypoint limits activation but does not neutralize the published registry payloa...