Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 10:23 UTC. Ordered by latest scan.
This is active, automatic credential and secret harvesting followed by transfer to an unrelated external endpoint. The behavior is concrete data theft, not a package-aligned capability.
This is active credential and secret exfiltration triggered by importing the package. The absence of an install hook does not mitigate the concrete import-time attack.
The package performs active, import-time collection and external transmission of credentials and secrets. This is concrete data exfiltration behavior.
This is active import-time credential and secret exfiltration to an unrelated hard-coded endpoint. The absence of an install hook does not mitigate the malicious runtime behavior.