Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 02:14 UTC. Ordered by latest scan.
Source directly implements an unconsented install-time exfiltration chain rather than legitimate package behavior. The static hint is confirmed by the manifest and complete source inspect...
Source inspection confirms a concrete, automatic install-time telemetry and IP-exfiltration chain, not merely suspicious primitives. The behavior is unnecessary for package installation a...
Source inspection confirms concrete install-time network collection and telemetry exfiltration of the installer host's public IP to a package-controlled Sentry project. No broader payload...
Direct source inspection confirms automatic remote code loading and a browser proxy/service-worker stack that handles routed requests and cookies. There is no npm lifecycle execution, but...