Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 03:45 UTC. Ordered by latest scan.
Source inspection confirms unconsented install-time data collection and import-time exfiltration to an obfuscated remote endpoint. This is malicious behavior, not a package-aligned Electr...
Static source inspection confirms deliberate credential/config harvesting and exfiltration behind misleading helper/hash names and an obfuscated endpoint. Lack of lifecycle hooks lowers a...
Source inspection confirms concrete unconsented environment harvesting during postinstall and a runtime network path that encodes the staged marker into a remote request. This is not nece...
Source inspection confirms concrete install-time credential harvesting and exfiltration in postinstall.js, unrelated to the package's date utility functionality. This is malicious supply-...