Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:02 UTC. Ordered by latest scan.
This is active, automatic credential and secret exfiltration through the package entrypoint. The external destination is unrelated to the local AWS metadata and Kubernetes secret sources.
The source implements active, automatic collection of sensitive cloud and local secrets followed by export to an unrelated endpoint. The behavior is malicious data exfiltration.
The package contains active, import-triggered collection and external transmission of cloud credentials and local secrets. This is concrete credential and data exfiltration.
This is active, automatic credential and secret exfiltration from the package entry point. The behavior is concrete malware rather than a guarded administrative capability.