Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 01:28 UTC. Ordered by latest scan.
This is a concrete import-time malware chain with stealthy persistence and credential exfiltration, unrelated to the advertised Solana utility functions.
This is concrete import-time malware behavior, not a package-aligned validation feature. The absence of npm lifecycle hooks does not mitigate the delayed runtime dropper and credential ex...
Direct source inspection confirms a concealed import-time persistence and credential-exfiltration chain. The benign SDK facade and absence of lifecycle hooks do not mitigate this runtime...
Source inspection confirms concrete, automatic install-time data exfiltration through lifecycle hooks. The package has no implementation supporting a legitimate purpose for these calls.