Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 23:51 UTC. Ordered by latest scan.
Direct source inspection confirms runtime cookie exfiltration behind a React icon component. The lack of lifecycle scripts does not mitigate the rendered-component attack surface.
Direct source inspection confirms concrete browser cookie exfiltration on component render. The absence of lifecycle hooks limits the trigger but does not mitigate the malicious runtime b...
Direct source inspection confirms runtime cookie exfiltration to hard-coded external endpoints. The absence of lifecycle hooks does not mitigate this malicious browser-side behavior.
Direct source inspection confirms unconsented install-time host fingerprinting and external exfiltration. This is concrete malicious behavior, not merely a suspicious primitive.