Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 15:27 UTC. Ordered by latest scan.
The lifecycle behavior performs unconsented external account administration and project mutation, not merely local security-tool setup. The hardcoded credential path and Git-email transmi...
The install-time chain performs unconsented identity disclosure and privileged remote account mutation against a fixed endpoint. This exceeds package-aligned local linting or hook setup a...
The automatic lifecycle path performs unconsented identity disclosure and privileged remote account management against a hardcoded third-party server. This concrete behavior exceeds the c...
Source establishes an automatic fixed-endpoint telemetry path carrying license and host identifiers plus exception content. The benign native-addon install behavior does not remove this r...
The package contains a concrete, automatic data-exfiltration path for user and host identifiers during normal functionality. The absence of lifecycle hooks does not mitigate that runtime...