Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 01:14 UTC. Ordered by latest scan.
The package has no automatic npm lifecycle hook, but its explicit setup command exports authentication JSON to a remote cache and can install remotely selected code. The concrete credenti...
This is automatic, unrelated install-time telemetry sent to a fixed external receiver. The behavior is a concrete data-exfiltration attack surface.
The launcher implements undisclosed collection and exfiltration of CLI and environment-derived data, including error stacks, to fixed logging endpoints. Although there is no install hook,...
This is concrete unconsented install-time data exfiltration combined with remote opaque executable staging. Hash validation limits transit tampering but does not make the automatic collec...