Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 15:50 UTC. Ordered by latest scan.
Source inspection confirms configured external logging of rich application records to embedded webhook receivers. The absence of install hooks reduces scope but does not remove the concre...
Source inspection confirms an active, hard-coded external logging path that serializes runtime records and is enabled by default for ScanOrder. No install-time behavior was found, but the...
Direct source inspection confirms an install-time HTTPS exfiltration chain. The package has no apparent functional implementation beyond collecting and transmitting host data.
Source confirms a hardcoded non-HTTPS IP default receiving bearer-authenticated activity uploads. The absence of lifecycle scripts limits propagation but does not remove the concrete cred...