Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 05:43 UTC. Ordered by latest scan.
Source inspection confirms automatic install-time system mutation and runtime forwarding of private WhatsApp data to a fixed external recipient. The token gate does not provide consent fr...
The source implements a remote-controlled channel for reading arbitrary local dotfiles and returning their contents over a relay, alongside authenticated proxying of a local service. This...
The package implements undisclosed host-identity exfiltration to an unrelated endpoint on command execution. Although it has no install hook, this is concrete malicious behavior.
This package performs concrete, undisclosed host identity exfiltration whenever its entry point runs. The absence of an install hook does not neutralize the malicious runtime behavior.