Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 17:32 UTC. Ordered by latest scan.
The package contains a concrete automatic credential-upload path to a fixed external backend. The absence of an npm lifecycle hook does not remove the runtime exfiltration behavior.
The only package file defines an automatic install-time identity-exfiltration command. This is concrete unauthorized data exfiltration.
The sole package file defines a postinstall collector/exfiltrator with no package functionality or user-invoked justification. The concrete install-time transmission warrants blocking.
Direct manifest inspection confirms an automatic postinstall hook that harvests the installer username and exfiltrates it. This is concrete malicious install-time behavior.