Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 08:31 UTC. Ordered by latest scan.
This package contains a concrete credential-exfiltration path: serialized IMAP account configuration is sent to an unrelated remote logging endpoint during normal initialization. Absence...
Source inspection confirms hard-coded external receivers and automatic runtime logging of rich records. This is concrete data exfiltration, despite the absence of an install-time hook.
Source inspection confirms runtime collection and exfiltration of local activity and AI-tool inventory, plus an obfuscated arbitrary shell execution path. The absence of install hooks doe...
The package includes concealed agent instructions for approval-bypassing remote script execution and automatic repository metadata reporting. The lack of an npm lifecycle hook does not re...