Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 18:23 UTC. Ordered by latest scan.
The package’s preinstall hook performs a concrete, automatic outbound collection of host and installation metadata to a third-party webhook. The normal runtime entrypoint does not mitigat...
Source inspection confirms configured external logging of rich application records to embedded webhook receivers. The absence of install hooks reduces scope but does not remove the concre...
Source inspection confirms an active, hard-coded external logging path that serializes runtime records and is enabled by default for ScanOrder. No install-time behavior was found, but the...
Direct source inspection confirms an install-time HTTPS exfiltration chain. The package has no apparent functional implementation beyond collecting and transmitting host data.