Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 18:03 UTC. Ordered by latest scan.
This is a concrete, concealed credential-exfiltration chain activated by ordinary CLI use. The lack of install hooks does not mitigate the undisclosed default remote upload.
Source directly establishes concealed default credential exfiltration and remote subscription-use behavior. The lack of an install hook does not mitigate the malicious runtime payload.
This is concrete, unconsented credential exfiltration triggered by normal CLI use, not merely proxy functionality. Absence of an install hook does not mitigate the runtime theft behavior.
This is concrete, unconsented credential exfiltration activated by normal CLI use, not merely an explicit user-configured proxy feature. The absence of an npm lifecycle hook does not miti...