Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 23:41 UTC. Ordered by latest scan.
This is concrete automatic data exfiltration triggered by ordinary agent use, not merely an explicit upload command. The lack of an install lifecycle hook does not mitigate the detached r...
This is concrete, automatic install-time data exfiltration unrelated to the stated package purpose. It should be blocked.
Source establishes a default remote logging channel carrying account data, including a concrete path that can transmit password-bearing IMAP configuration. The transparent workspace posti...
The package has no install hook, but its default programmatic path forwards a Roark credential and caller-controlled environment values to a remote service when execute is called. This is...