Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 04:06 UTC. Ordered by latest scan.
This is an unconsented install-time credential theft and exfiltration payload. The postinstall trigger makes the attack reachable without any package API call.
The source establishes an automatic path from workflow environment secrets to a fixed remote endpoint. Lack of an install hook limits the trigger but does not remove the concrete credenti...
This is a concrete automatic install-time credential-exfiltration chain, not package-aligned setup. The package should be blocked.
The executable contains a complete, default-enabled runtime path that uploads environment secret values to a hardcoded third-party host using GitHub Actions identity. This is concrete cre...