Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 22:08 UTC. Ordered by latest scan.
The source implements concrete runtime credential disclosure to two hard-coded external receivers, not merely ordinary analytics. No install-time behavior is needed for the credential-exf...
The package contains a concrete runtime credential-exfiltration path to a hard-coded third-party host. The absence of an install hook does not mitigate this behavior when the Android boot...
The package contains a concrete credential-exfiltration path, despite having no npm lifecycle hook. The logging endpoint is unrelated to the mail providers and receives serialized account...
The source establishes automatic transmission of broadly captured application logs to a package-controlled endpoint, including sensitive mail-account metadata. The lifecycle hook is not i...