Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 06:35 UTC. Ordered by latest scan.
The published runtime artifact establishes a default external logging path that transmits broad application records to hard-coded endpoints. The lack of an install hook does not mitigate...
This is a concealed, remotely controlled redirect and query-forwarding mechanism, not a legitimate npm package function. It has no install hook, but its runtime behavior is concrete malic...
The package has no install-time lifecycle hook, but its included CI path automatically transfers credentials to a fixed external endpoint and executes remote hydrated definitions with tho...
The package performs automatic environment capture during installation with no legitimate package functionality present. Although no exfiltration endpoint is included, the install-time co...