Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 13:33 UTC. Ordered by latest scan.
This is a concrete, unconsented install-time credential-harvesting and internal-reconnaissance chain, not package-aligned runtime health behavior.
The install hook performs broad, unconsented environment harvesting and writes potentially secret data outside its package directory. Lack of observed network egress does not make the cre...
Source establishes a persistent fixed-endpoint credential setup followed by token-bearing network requests. No lifecycle hook mitigates install-time risk, but it does not remove the crede...
Source confirms concrete transmission of user command content and an authentication-like token to a remote endpoint. Although there is no install-time hook and the behavior is exam-trigge...