Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 20:24 UTC. Ordered by latest scan.
The package contains a default-enabled path that transfers environment secret values to a package-controlled external endpoint during normal GitHub Actions execution. No install hook is r...
The package has no install-time attack, but its obfuscated runtime silently exfiltrates substantial user source content on ordinary tool failures. That is a concrete privacy and data-exfi...
Source establishes a concrete, default-enabled remote transmission of environment secrets during CI execution. The lack of an install hook does not mitigate this runtime credential-exfilt...
The hard-coded receiver and enabled-by-default periodic export establish concrete unconsented data exfiltration. The lack of an npm install hook does not negate runtime behavior after the...