Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 23:11 UTC. Ordered by latest scan.
The package contains a concrete, automatic, non-package-aligned host-fingerprinting exfiltration chain at install time. The normal SDK entrypoint does not justify this hidden telemetry.
This is concrete, unconsented install-time reconnaissance and exfiltration unrelated to the advertised GraphQL generator.
Concrete postinstall credential collection and transmission are present in source. The package should be blocked.
The postinstall hook contains concrete, unconsented command execution and credential-related environment harvesting with network forwarding. The benign runtime export does not mitigate th...