Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 22:28 UTC. Ordered by latest scan.
Direct source inspection confirms unconsented install-time exfiltration and remote-access persistence. This is concrete malicious behavior, not a package-aligned feature.
Direct source inspection confirms deliberate credential exfiltration on the exported runtime path. The lack of lifecycle scripts limits automatic execution but does not remove the concret...
This is not date-parsing functionality: source inspection confirms obfuscated browser injection and unconsented data exfiltration activated by the exported API. The lack of lifecycle hook...
Source inspection confirms a concrete browser-side form-data exfiltration chain activated by the package's exported API. The absence of install hooks does not mitigate the malicious runti...