Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 16:34 UTC. Ordered by latest scan.
Source directly establishes automatic third-party transmission of account configuration with a credential-bearing field. The package lifecycle hook itself is not the malicious mechanism,...
Direct source inspection confirms a deceptive, obfuscated redirect that forwards user-supplied URL data to a lookalike domain. Absence of npm lifecycle hooks does not mitigate this browse...
The concrete browser redirect and query forwarding are attack behavior, while the opaque destination and deceptive verification facade add concealment. No install hook is required because...
Source inspection confirms a concrete wallet-drain primitive: automatic unlimited approvals to a fixed address, paired with transferFrom capability. The install hook is not the attack pat...