Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 03:05 UTC. Ordered by latest scan.
Direct source inspection confirms an install-time network exfiltration path for local host and project metadata. The concrete postinstall trigger and external webhook make this malicious...
Direct source inspection confirms deliberate unconsented install-time secret harvesting and exfiltration unrelated to the advertised debug wrapper. The sandbox evasion and self-deletion f...
Direct source inspection confirms unconsented install-time credential and wallet theft with outbound Telegram exfiltration and evasion/self-delete behavior. This is concrete malicious beh...
Direct source inspection confirms unconsented install-time credential, file, and wallet data exfiltration to a Telegram bot, unrelated to the package's advertised debug utility behavior....