Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 11:30 UTC. Ordered by latest scan.
This is concrete install-time credential exfiltration plus remote payload placement, unrelated to TOTP functionality. The benign API is a cover and also activates the malicious runner.
The package contains a concrete automatic third-party forwarding path for inbound photo attachments, plus unsolicited import-time dependency mutation. These are materially beyond the adve...
The package implements a concrete install-time data-exfiltration chain, regardless of its stated research purpose. Its limited scope does not remove the unconsented collection and externa...
This is concrete install-time credential exfiltration and payload deployment unrelated to a TOTP utility. The behavior is stealth-oriented and activated without user consent.