Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 10:49 UTC. Ordered by latest scan.
This is concrete, unconsented install-time credential/configuration exfiltration. The endpoint is intentionally concealed and the lifecycle hook suppresses errors.
The source establishes a concrete credential-harvesting and remote-authentication chain, not merely support for user-provided environment keys. Although execution is CLI-invoked and there...
Source inspection confirms a credential-harvesting extension with broad site access and a hard-coded external default endpoint. The user confirmation does not remove the concrete remote c...
The source confirms automatic lifecycle execution and external DNS transmission of host-derived data. The inert runtime export does not mitigate the install-time behavior.