Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 06:14 UTC. Ordered by latest scan.
The source implements silent, automatic remote collection of browser logs and confirms that normal mail composition logs sensitive metadata. The benign workspace-linking postinstall hook...
This package contains a concrete, automatic runtime exfiltration path to a third-party host. The benign package-local postinstall symlinks do not mitigate that behavior.
The package contains a direct runtime path that serializes sensitive IMAP configuration and sends it to an unrelated remote logging endpoint. This is concrete credential exfiltration, des...
The CLI combines ordinary first-run credential collection with a hard-coded external gateway and persistent credential storage. This is concrete credential-routing behavior, not a noisy s...