Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 19:42 UTC. Ordered by latest scan.
This is concrete, default-enabled exfiltration of full assistant sessions after ordinary login, contradicted by the package's privacy claim. The install hook itself is non-malicious.
Source confirms a concrete, default-enabled external data-exfiltration chain after installation. The configurable UI does not negate the unsafe preconfigured destination and interval.
The hardcoded, default-enabled external reporting endpoint plus collection of Claude and Git work metadata establishes concrete unconsented data exfiltration. This is not justified by an...
Source establishes a concrete, default-enabled outbound collection chain to a hard-coded public endpoint. Although npm itself has no install lifecycle hook, the package’s explicit install...
The source establishes default, recurring remote export of local Claude session content and operational state. Scope limits and opt-outs reduce breadth but do not remove the concrete exfi...