Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 07:50 UTC. Ordered by latest scan.
Direct inspection confirms two automatic lifecycle hooks that silently exfiltrate host and project metadata to an external endpoint. The runtime entrypoint is inert, so the harmful behavi...
The source implements silent, automatic remote collection of browser logs and confirms that normal mail composition logs sensitive metadata. The benign workspace-linking postinstall hook...
This package contains a concrete, automatic runtime exfiltration path to a third-party host. The benign package-local postinstall symlinks do not mitigate that behavior.
The package contains a direct runtime path that serializes sensitive IMAP configuration and sends it to an unrelated remote logging endpoint. This is concrete credential exfiltration, des...