Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 00:46 UTC. Ordered by latest scan.
Source establishes a concrete surveillance-and-exfiltration chain paired with stealth persistence and proctoring evasion. The benign postinstall hook does not mitigate the malicious runti...
The package contains concrete, unconsented install-time shell execution that probes an internal-looking service and exfiltrates retrieved content to an external OAST domain. This is malic...
This is concrete import-time credential and host-information exfiltration with no package-aligned functionality. The absence of lifecycle hooks does not mitigate execution when consumers...
Source inspection confirms a concrete import-time credential and host-fingerprint exfiltration chain to an unrelated hard-coded endpoint. This is malicious behavior despite the absence of...