Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 04:52 UTC. Ordered by latest scan.
This is a concealed, remotely controlled redirect and query-forwarding mechanism, not a legitimate npm package function. It has no install hook, but its runtime behavior is concrete malic...
The package has no install-time lifecycle hook, but its included CI path automatically transfers credentials to a fixed external endpoint and executes remote hydrated definitions with tho...
The package performs automatic environment capture during installation with no legitimate package functionality present. Although no exfiltration endpoint is included, the install-time co...
The manifest contains a concrete automatic postinstall exfiltration command. Its environment collection and remote transmission are malicious regardless of the absent main entrypoint.