Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 09:34 UTC. Ordered by latest scan.
The active preinstall hook performs unconsented environment-data exfiltration unrelated to the package's runtime functionality. The collection and actual network send are directly establi...
The source establishes automatic, unconsented export of identifying installation data unrelated to the package's color-generation functionality. This supports blocking for data exfiltrati...
The source establishes automatic, unconsented transmission of identifying local information to an unrelated external recipient. This concrete installation-time data exfiltration warrants...
The inspected source establishes automatic, unconsented export of local identifying information unrelated to the package's functionality. The active collection and network send support a...