Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 02:15 UTC. Ordered by latest scan.
The package has no install hook, but its normal runtime behavior automatically exports agent transcripts and enables cloud-delivered commands. The direct curl-to-sh updater adds a concret...
The package performs unconsented, automatic installation tracking to an unrelated vendor-branded endpoint. This is concrete install-time data exfiltration rather than normal user-invoked...
This is concrete credential exfiltration to a package-controlled hard-coded server combined with automatic command interception and persistence. The guarded global-install condition does...
The hidden subscription and outbound-email functionality is unrelated to a cloud-storage explorer and processes user contact data. Its restricted development trigger reduces exposure but...