Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 17:14 UTC. Ordered by latest scan.
Source establishes a concrete, default-enabled outbound collection chain to a hard-coded public endpoint. Although npm itself has no install lifecycle hook, the package’s explicit install...
The source establishes default, recurring remote export of local Claude session content and operational state. Scope limits and opt-outs reduce breadth but do not remove the concrete exfi...
Source directly establishes transmission of serialized IMAP configuration, including a supported password field, to a remote logging endpoint. The install hook is unrelated and does not m...
The deceptive UI, intentional concealment, and unconditional forwarding of browser query data to an obfuscated destination establish a concrete exfiltration chain. Lack of install hooks d...