Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 03:45 UTC. Ordered by latest scan.
The package performs unconsented postinstall environment collection, internal metadata probing, persistence, and third-party reporting. Its self-description does not neutralize these conc...
The package contains an automatic install-time data-collection and external-egress path, not merely an inert test fixture. Its self-described testing purpose does not provide consumer con...
The hidden, hard-coded secondary upload of local attachment contents is concrete data exfiltration. Explicit user selection of an issue attachment does not consent to an undisclosed trans...
The install hook itself is limited, but the executable contains an automatic hard-coded network beacon that discloses host metadata on normal use. The self-dependency adds supply-chain risk.