Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:02 UTC. Ordered by latest scan.
The package contains an automatic install hook connected to active credential harvesting and outbound transmission. This is concrete malicious data exfiltration.
The package contains a concrete automatic install-time collection and outbound transmission of local system identifiers. This is malicious data exfiltration rather than ordinary package s...
The package contains an automatic preinstall hook that collects local host metadata and transmits it to a hard-coded third-party endpoint. This is concrete install-time data exfiltration.
The active executable performs credential and local-file collection followed by a network send. Its npm command name makes the behavior especially likely to be triggered through command c...