Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 03:05 UTC. Ordered by latest scan.
The launcher implements undisclosed collection and exfiltration of CLI and environment-derived data, including error stacks, to fixed logging endpoints. Although there is no install hook,...
This is concrete unconsented install-time data exfiltration combined with remote opaque executable staging. Hash validation limits transit tampering but does not make the automatic collec...
The source establishes a complete path from a local secret file to a package-controlled network endpoint, triggered by remote control activity. The harmless postinstall message does not m...
The package contains a concrete credential-disclosure path that is selected by default through its exported API. The lack of an install hook and safer CLI default do not remove this libra...