Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 16:56 UTC. Ordered by latest scan.
This is concrete, default-enabled data exfiltration to a hardcoded third-party endpoint after installation. It is not justified by an npm lifecycle hook, but user invocation does not cure...
This is concrete, unconsented install-time reconnaissance and exfiltration rather than a package-aligned function. The environment guard narrows targeting but does not remove the maliciou...
This is concrete unconsented install-time reconnaissance, exfiltration, persistence, and filesystem mutation. The path gate and stated research purpose do not remove the malicious behavio...
The cwd guard narrows targeting but does not make the lifecycle-triggered internal reconnaissance consensual. Collection is retained locally and TLS validation is disabled.