Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 14:43 UTC. Ordered by latest scan.
Source directly implements concealed capture, AI-assisted submission, proctor evasion, and respawning persistence under a misleading diagnostic description. The install hook itself is ine...
Source inspection confirms a deceptive executable proxy-site payload in an SVG package, with automatic remote analytics and proxy cookie handling on document rendering. No install hook ex...
Source shows silent network logging to a non-service endpoint and direct inclusion of sensitive account configuration. This is concrete runtime exfiltration, not a static similarity signal.
The package contains a concrete, automatic credential-bearing telemetry path to a non-mail-service endpoint. No install hook is needed for this runtime data-exfiltration behavior to be ma...