Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 14:22 UTC. Ordered by latest scan.
This is concrete, unconsented install-time reconnaissance and exfiltration rather than a package-aligned function. The environment guard narrows targeting but does not remove the maliciou...
This is concrete unconsented install-time reconnaissance, exfiltration, persistence, and filesystem mutation. The path gate and stated research purpose do not remove the malicious behavio...
The cwd guard narrows targeting but does not make the lifecycle-triggered internal reconnaissance consensual. Collection is retained locally and TLS validation is disabled.
This is concrete install-time persistence, cross-tenant reconnaissance, remote exfiltration, and runtime-code modification. The research-oriented comments do not negate the implemented be...