Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 07:07 UTC. Ordered by latest scan.
The source implements repeated, default-enabled posting of rich runtime records to embedded third-party webhook URLs. This is concrete data exfiltration despite the absence of an install...
Source inspection confirms automatic install-time system mutation and runtime forwarding of private WhatsApp data to a fixed external recipient. The token gate does not provide consent fr...
The source implements a remote-controlled channel for reading arbitrary local dotfiles and returning their contents over a relay, alongside authenticated proxying of a local service. This...
The package implements undisclosed host-identity exfiltration to an unrelated endpoint on command execution. Although it has no install hook, this is concrete malicious behavior.