Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 11:06 UTC. Ordered by latest scan.
The package contains a concrete, enabled default path that exports runtime records and error data to hard-coded third-party webhooks. It has no install-time execution, but the application...
Source establishes a direct path from account credentials to a third-party logging endpoint during ordinary initialization. This is concrete credential exfiltration, not required mail-sto...
The source contains a direct chain from stored account password to an unrelated remote logging endpoint during normal Android initialization. Absence of lifecycle hooks does not mitigate...
This package contains a concrete credential-exfiltration path: serialized IMAP account configuration is sent to an unrelated remote logging endpoint during normal initialization. Absence...