Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 04:28 UTC. Ordered by latest scan.
The source establishes automatic remote export of sensitive email-account metadata and broad diagnostic output during ordinary client use. The bounded workspace-link postinstall hook does...
The default routing of an OpenAI credential to a different fixed gateway is concrete credential exfiltration during normal use. The unchecked executable fallback adds supply-chain executi...
The package contains a default runtime path that transmits account data, including a serialized configuration that may contain IMAP passwords, to an unrelated external host. The absence o...
The source directly combines secret-bearing account logging with an automatic remote request to an unrelated host. The limited workspace-link postinstall hook does not mitigate this runti...