Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 23:51 UTC. Ordered by latest scan.
Source inspection confirms automatic upload of agent transcripts and credential metadata to server-directed endpoints during normal runtime. This is concrete data exfiltration behavior, n...
This is a concrete credential-exfiltration path: a password-bearing account object is serialized into a remote logging request. The lack of npm lifecycle hooks does not mitigate the runti...
The package contains an undisclosed runtime exfiltration path to a non-service host for broad console and account-sync telemetry. Although its postinstall hook is benign, the runtime data...
Source inspection confirms a broad agent-hook collection and upload path to a fixed HTTP IP with bearer authentication. The lack of an npm lifecycle hook reduces automatic-install risk bu...